Architectures for Detecting Interleaved Multi-Stage Network Attacks Using Hidden Markov Models

31Citations
Citations of this article
41Readers
Mendeley users who have this article in their library.
Get full text

Abstract

With the growing amount of cyber threats, the need for development of high-assurance cyber systems is becoming increasingly important. The objective of this article is to address the challenges of modeling and detecting sophisticated network attacks, such as multiple interleaved attacks. We present the interleaving concept and investigate how interleaving multiple attacks can deceive intrusion detection systems. Using one of the important statistical machine learning (ML) techniques, Hidden Markov Models (HMM), we develop two architectures that take into account the stealth nature of the interleaving attacks, and that can detect and track the progress of these attacks. These architectures deploy a database of HMM templates of known attacks and exhibit varying performance and complexity. For performance evaluation, in the presence of multiple multi-stage attack scenarios, various metrics are proposed which include (1) attack risk probability, (2) detection error rate, and (3) the number of correctly detected stages. Extensive simulation experiments are used to demonstrate the efficacy of the proposed architectures.

Cite

CITATION STYLE

APA

Shawly, T., Elghariani, A., Kobes, J., & Ghafoor, A. (2021). Architectures for Detecting Interleaved Multi-Stage Network Attacks Using Hidden Markov Models. IEEE Transactions on Dependable and Secure Computing, 18(5), 2316–2330. https://doi.org/10.1109/TDSC.2019.2948623

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free