Memorias de investigación
Artículos en revistas:
Real-time multistep attack prediction based on Hidden Markov Models
Año:2017

Áreas de investigación
  • Ciencias de la computación y tecnología informática

Datos
Descripción
A novel method based on the Hidden Markov Model is proposed to predict multistep attacks using IDS alerts. We consider the hidden states as similar phases of a particular type of attack. As a result, it can be easily adapted to multistep attacks and foresee the next steps of an attacker. To achieve this goal, a preliminary off-line training phase based on observations will be required. These observations are obtained by matching the IDS alert information with a database previously built for this purpose using a clusterization method from the CVE global database to avoid overfitting. The training model is performed using both unsupervised and supervised algorithms. Once the training is completed and probability matrices are computed, the prediction module compute the best state sequence based on the state probability for each step of the multistep attack in progress using the Viterbi and forward-backward algorithms. The training model includes the mean number of alerts and the number of alerts in progress to assist in obtaining the final attack probability. The model is analyzed for DDoS phases because it is a great problem in all Internet services. The proposed method is validated into a virtual DDoS scenario using current vulnerabilities. The results proving the system?s ability to perform real-time prediction.
Internacional
Si
JCR del ISI
Si
Título de la revista
Ieee Transactions on Dependable And Secure Computing
ISSN
1545-5971
Factor de impacto JCR
1,592
Información de impacto
Datos JCR del año 2015
Volumen
DOI
10.1109/TDSC.2017.2751478
Número de revista
Desde la página
1
Hasta la página
14
Mes
SIN MES
Ranking

Esta actividad pertenece a memorias de investigación

Participantes

Grupos de investigación, Departamentos, Centros e Institutos de I+D+i relacionados
  • Creador: Grupo de Investigación: Redes y Servicios de Telecomunicación e Internet
  • Centro o Instituto I+D+i: Centro de I+d+i en Procesado de la Información y Telecomunicaciones
  • Departamento: Ingeniería de Sistemas Telemáticos