返回
Architectures for Detecting Interleaved Multi-Stage Network Attacks Using Hidden Markov Models
DOI:10.1109/TDSC.2019.2948623.png)
摘要
En 中文
With the growing amount of cyber threats, the need for development of high-assurance cyber systems is becoming increasingly important. The objective of this article is to address the challenges of modeling and detecting sophisticated network attacks, such as multiple interleaved attacks. We present the interleaving concept and investigate how interleaving multiple attacks can deceive intrusion detection systems. Using one of the important statistical machine learning (ML) techniques, Hidden Markov Models (HMM), we develop two architectures that take into account the stealth nature of the interleaving attacks, and that can detect and track the progress of these attacks. These architectures deploy a database of HMM templates of known attacks and exhibit varying performance and complexity. For performance evaluation, in the presence of multiple multi-stage attack scenarios, various metrics are proposed which include (1) attack risk probability, (2) detection error rate, and (3) the number of correctly detected stages. Extensive simulation experiments are used to demonstrate the efficacy of the proposed architectures.
Keyword:
Hidden Markov models
Intrusion detection
Computer crime
Computer architecture
Complexity theory
Servers
Cyber systems
network security
intrusion detection
Hidden Markov Model
interleaved attacks
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
7.5
论文数:
2.4K
被引数:
9.6K
机构
引用论文
A TUTORIAL ON HIDDEN MARKOV-MODELS AND SELECTED APPLICATIONS IN SPEECH RECOGNITION关于语音识别中的隐马尔可夫模型和选定应用的教程
PROCEEDINGS OF THE IEEE
IF25.9

