首页> 外文期刊>IEEE transactions on dependable and secure computing >Real-Time Multistep Attack Prediction Based on Hidden Markov Models
【24h】

Real-Time Multistep Attack Prediction Based on Hidden Markov Models

机译:基于隐马尔可夫模型的实时多步攻击预测

获取原文
获取原文并翻译 | 示例
           

摘要

A novel method based on the Hidden Markov Model is proposed to predict multistep attacks using IDS alerts. We consider the hidden states as similar phases of a particular type of attack. As a result, it can be easily adapted to multistep attacks and foresee the next steps of an attacker. To achieve this goal, a preliminary off-line training phase based on observations will be required. These observations are obtained by matching the IDS alert information with a database previously built for this purpose using a clusterization method from the CVE global database to avoid overfitting. The training model is performed using both unsupervised and supervised algorithms. Once the training is completed and probability matrices are computed, the prediction module compute the best state sequence based on the state probability for each step of the multistep attack in progress using the Viterbi and forward-backward algorithms. The training model includes the mean number of alerts and the number of alerts in progress to assist in obtaining the final attack probability. The model is analyzed for DDoS phases because it is a great problem in all Internet services. The proposed method is validated into a virtual DDoS scenario using current vulnerabilities. The results proving the system & x0027;s ability to perform real-time prediction.
机译:提出了一种基于隐马尔可夫模型的新方法,以预测使用IDS警报的多步攻击。我们认为隐藏的状态作为特定类型攻击的相似阶段。结果,它可以很容易地适应多步攻击并预见攻击者的后续步骤。为实现这一目标,需要基于观察的初步离线训练阶段。通过使用来自CVE全球数据库的集群化方法将IDS警报信息与先前为此目的构建的数据库匹配来获得这些观察结果,以避免过度装备。使用无监督和监督算法进行培训模型。一旦训练完成并且计算了概率矩阵,预测模块基于使用维特比和前后算法正在进行的多步攻击的每个步骤的状态概率来计算最佳状态序列。培训模型包括警报的平均数量和正在进行的警报数量,以帮助获得最终攻击概率。分析模型的DDOS阶段,因为它是所有互联网服务中的一个很大的问题。使用当前漏洞,所提出的方法被验证为虚拟DDOS场景。结果证明了系统和X0027;■执行实时预测的能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号