Real-time Intrusion Prevention and Security Analysis of Networks using HMMs

被引:0
|
作者
Haslum, Kjetil [1 ]
Moe, Marie E. G. [1 ]
Knapskog, Svein J. [1 ]
机构
[1] Norwegian Univ Sci & Technol, Ctr Quantifiable Qual Serv Commun Syst, N-7491 Trondheim, Norway
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper we propose to use a hidden Markov model (HMM) to model sensors for an intrusion prevention system (IPS). Observations from different sensors are aggregated in the HMM and the intrusion frequency security metric is estimated. We use a Markov model that captures the interaction between (he attacker and the network to model and predict the next step of an attacker. A new HMM is created and used for updating the estimated system state for each observation, based on the sensor trustworthiness and the time since last observation processed. Our objective is to calculate and maintain a state probability distribution that can be used for intrusion prediction and prevention. We show how our sensor model can be applied to an IPS architecture based on intrusion detection system (IDS) sensors, real-time traffic surveillance and online risk assessment. Our approach is illustrated by a small case study.
引用
收藏
页码:902 / 909
页数:8
相关论文
共 50 条
  • [1] REAL-TIME TRAFFIC DETECTION and ANALYSIS of NETWORK SECURITY INTRUSION ATTACK: SNORT INTRUSION PREVENTION SYSTEM
    Zhou A.L.
    Telecommunications and Radio Engineering (English translation of Elektrosvyaz and Radiotekhnika), 2020, 79 (12): : 1055 - 1062
  • [2] Real-time intrusion prevention and anomaly analyze system for corporate networks
    Dutkevych, Taras
    Piskozub, Andrian
    Tymoshyk, Nazar
    IDAACS 2007: PROCEEDINGS OF THE 4TH IEEE WORKSHOP ON INTELLIGENT DATA ACQUISITION AND ADVANCED COMPUTING SYSTEMS: TECHNOLOGY AND APPLICATIONS, 2007, : 599 - +
  • [3] A novel honeypot based security approach for real-time intrusion detection and prevention systems
    Baykara, Muhammet
    Das, Resul
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2018, 41 : 103 - 116
  • [4] A Real-Time Intrusion Detection Algorithm for Network Security
    El-Bakry, Hazem M.
    Mastorakis, Nikos
    PROCEEDINGS OF THE 8TH WSEAS INTERNATIONAL CONFERENCE ON APPLIED INFORMATICS AND COMMUNICATIONS, PTS I AND II: NEW ASPECTS OF APPLIED INFORMATICS AND COMMUNICATIONS, 2008, : 533 - +
  • [5] A real-time intrusion detection algorithm for network security
    El-Bakry, Hazem M.
    Mastorakis, Nikos
    2008, WSEAS (07):
  • [6] Real-Time Intrusion Detection and Prevention with Neural Network in Kernel using eBPF
    Zhang, Junyu
    Chen, Pengfei
    He, Zilong
    Chen, Hongyang
    Li, Xiaoyun
    2024 54TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, DSN 2024, 2024, : 416 - 428
  • [7] Real-Time Network Intrusion Prevention System Using Incremental Feature Generation
    Uhm, Yeongje
    Pak, Wooguil
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 70 (01): : 1631 - 1648
  • [8] A real-time head nod and shake detector using HMMs
    Tan, WZ
    Rong, G
    EXPERT SYSTEMS WITH APPLICATIONS, 2003, 25 (03) : 461 - 466
  • [9] Real-time Security Solution for Automatic Detection and Tracking of Intrusion
    Bar, Debesh
    Pande, Dhruv
    Sandhu, Manveer Singh
    Upadhyaya, Vikas
    2015 THIRD INTERNATIONAL CONFERENCE ON IMAGE INFORMATION PROCESSING (ICIIP), 2015, : 399 - 402
  • [10] Real-time intrusion detection for ad hoc networks
    Stamouli, I
    Argyroudis, PG
    Tewari, H
    SIXTH IEEE INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS MOBILE AND MULTIMEDIA NETWORKS, PROCEEDINGS, 2005, : 374 - 380