Attacker Behaviour Profiling using Stochastic Ensemble of Hidden Markov Models

05/28/2019
by   Soham Deshmukh, et al.
0

Cyber threat intelligence is one of the emerging areas of focus in information security. Much of the recent work has focused on rule-based methods and detection of network attacks using Intrusion Detection algorithms. In this paper we propose a framework for inspecting and modelling the behavioural aspect of an attacker to obtain better insight predictive power on his future actions. For modelling we propose a novel semi-supervised algorithm called Fusion Hidden Markov Model (FHMM) which is more robust to noise, requires comparatively less training time, and utilizes the benefits of ensemble learning to better model temporal relationships in data. This paper evaluates the performances of FHMM and compares it with both traditional algorithms like Markov Chain, Hidden Markov Model (HMM) and recently developed Deep Recurrent Neural Network (Deep RNN) architectures. We conduct the experiments on dataset consisting of real data attacks on a Cowrie honeypot system. FHMM provides accuracy comparable to deep RNN architectures at significant lower training time. Given these experimental results, we recommend using FHMM for modelling discrete temporal data for significantly faster training and better performance than existing methods.

READ FULL TEXT

page 1

page 8

research
12/05/2015

Stochastic Collapsed Variational Inference for Hidden Markov Models

Stochastic variational inference for collapsed models has recently been ...
research
09/06/2011

Tech Report A Variational HEM Algorithm for Clustering Hidden Markov Models

The hidden Markov model (HMM) is a generative model that treats sequenti...
research
10/30/2019

Hidden Markov Models for sepsis detection in preterm infants

We explore the use of traditional and contemporary hidden Markov models ...
research
07/25/2018

Architectures for Detecting Real-time Multiple Multi-stage Network Attacks Using Hidden Markov Model

With the growing Cyber threats, the need to develop high assurance Cyber...
research
11/02/2022

Dormant Neural Trojans

We present a novel methodology for neural network backdoor attacks. Unli...
research
07/14/2019

On the Role of Time in Learning

By and large the process of learning concepts that are embedded in time ...
research
07/01/2016

Moving Toward High Precision Dynamical Modelling in Hidden Markov Models

Hidden Markov Model (HMM) is often regarded as the dynamical model of ch...

Please sign up or login with your details

Forgot password? Click here to reset