Evaluation of HMM-Based Network Intrusion Detection System for Multiple Multi-Stage Attacks

21Citations
Citations of this article
23Readers
Mendeley users who have this article in their library.
Get full text

Abstract

With the explosive growth of network security threats, there is a dire need to build secure network systems. In this article, we address the challenges of modeling and detecting advanced network attacks. In particular, we investigate how interleaving multiple multi-stage can exacerbate the stealthiness of the attack and deceive network intrusion detection systems. We design a detection architecture based on a leading statistical machine learning technique, HMM. The proposed architecture deploys a set of HMM templates of recognized multi-stage attacks to detect and track the progress of stealthy attacks. Extensive simulation experiments are conducted to assess the performance of the proposed architecture for multiple multi-stage attack scenarios in the presence of imperfect partitioning of network data streams and false alerts with various rates.

Cite

CITATION STYLE

APA

Shawly, T., Khayat, M., Elghariani, A., & Ghafoor, A. (2020). Evaluation of HMM-Based Network Intrusion Detection System for Multiple Multi-Stage Attacks. IEEE Network, 34(3), 240–248. https://doi.org/10.1109/MNET.001.1900426

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free