Architectures for Detecting Real-time Multiple Multi-stage Network Attacks Using Hidden Markov Model

07/25/2018
by   Tawfeeq Shawly, et al.
0

With the growing Cyber threats, the need to develop high assurance Cyber systems is becoming increasingly important. The objective of this paper is to address the challenges of modeling and detecting sophisticated and diversified network attacks. Using one of the important statistical machine learning (ML) techniques, Hidden Markov Models (HMM), we develop two architectures that can detect and track in real-time the progress of these organized attacks. These architectures are based on developing a database of HMM templates and exhibit varying performance and complexity. For performance evaluation, in the presence of multiple multi-stage attack scenarios, various metrics are proposed which include (1) attack risk probability, (2) detection error rate, and (3) the number of correctly detected stages. Extensive simulation experiments are used based on the DARPA2000 dataset to demonstrate the efficacy of the proposed architectures.

READ FULL TEXT
research
11/22/2021

PRISM: A Hierarchical Intrusion Detection Architecture for Large-Scale Cyber Networks

The increase in scale of cyber networks and the rise in sophistication o...
research
11/30/2018

Change Point Models for Real-time V2I Cyber Attack Detection in a Connected Vehicle Environment

Connected vehicle (CV) systems are cognizant of potential cyber attacks ...
research
06/03/2021

Attack Prediction using Hidden Markov Model

It is important to predict any adversarial attacks and their types to en...
research
03/05/2020

Change Point Models for Real-time Cyber Attack Detection in Connected Vehicle Environment

Connected vehicle (CV) systems are cognizant of potential cyber attacks ...
research
05/28/2019

Attacker Behaviour Profiling using Stochastic Ensemble of Hidden Markov Models

Cyber threat intelligence is one of the emerging areas of focus in infor...
research
03/23/2021

Detecting Phishing Sites – An Overview

Phishing is one of the most severe cyber-attacks where researchers are i...
research
05/17/2021

RAIDER: Reinforcement-aided Spear Phishing Detector

Spear Phishing is a harmful cyber-attack facing business and individuals...

Please sign up or login with your details

Forgot password? Click here to reset