A Markov Multi-Phase Transferable Belief Model for Cyber Situational Awareness

被引:13
|
作者
Ioannou, Georgios [1 ]
Louvieris, Panos [1 ]
Clewley, Natalie [2 ]
机构
[1] Brunel Univ, Dept Comp Sci, Uxbridge UB8 3PH, Middx, England
[2] Cranfield Univ, Def Acad, Ctr Elect Warfare Informat & Cyber, Shrivenham SN6 8LA, England
来源
IEEE ACCESS | 2019年 / 7卷 / 39305-39320期
关键词
APT; combination rule; conflict; cyberspace; kill-chain; Markov processes; prediction; sensor fusion; situational awareness; uncertainty; FUSING UNCERTAIN; COMBINATION;
D O I
10.1109/ACCESS.2019.2897923
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
eXfiltration Advanced Persistent Threats (XAPTs) increasingly account for incidents concerned with critical information exfiltration from High Valued Targets (HVTs). Existing Cyber Defence frameworks and data fusion models cannot cope with XAPTs due to a lack of provision for multi-phase attacks characterized by uncertainty and conflicting information. The Markov Multi-phase Transferable Belief Model (MM-TBM) extends the Transferable Belief Model to address the multi-phase nature of cyber-attacks and to obtain previously indeterminable Cyber SA. As a data fusion technique, MM-TBM constitutes a novel approach for performing hypothesis assessment and evidence combination across phases, by means of a new combination rule, called the Multi-phase Combination Rule with conflict Reset (MCR2). The impact of MM-TBM as a Cyber Situational Awareness capability and its implications as a multi-phase data fusion theory have been empirically validated through a series of scenario-based Cyber SA experiments for detecting, tracking, and predicting XAPTs.
引用
收藏
页码:39305 / 39320
页数:16
相关论文
共 50 条
  • [1] A Markov Multi-Phase Transferable Belief Model: An Application for predicting Data Exfiltration APTs
    Ioannou, Georgios
    Louvieris, Panos
    Clewley, Natalie
    Powell, Gavin
    [J]. 2013 16TH INTERNATIONAL CONFERENCE ON INFORMATION FUSION (FUSION), 2013, : 842 - 849
  • [2] A multi-phase network situational awareness cognitive task analysis
    Erbacher, Robert F.
    Frincke, Deborah A.
    Wong, Pak Chung
    Moody, Sarah
    Fink, Glenn
    [J]. INFORMATION VISUALIZATION, 2010, 9 (03) : 204 - 219
  • [3] A Computational Model of Cyber Situational Awareness
    Dobson, Geoffrey B.
    Carley, Kathleen M.
    [J]. SOCIAL, CULTURAL, AND BEHAVIORAL MODELING, SBP-BRIMS 2018, 2018, 10899 : 395 - 400
  • [4] Multi-phase epidemic model by a Markov chain
    Buccellato, Stefania Maria
    Tornatore, Elisabetta
    [J]. PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2008, 387 (14) : 3555 - 3562
  • [5] CRUSOE: Data Model for Cyber Situational Awareness
    Komarkova, Jana
    Husak, Martin
    Lastovicka, Martin
    Tovarnak, Daniel
    [J]. 13TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2018), 2019,
  • [6] A Markov game theoretic data fusion approach for cyber Situational awareness
    Shen, Dan
    Chen, Genshe
    Cruz, Jose B., Jr.
    Haynes, Leonard
    Kruger, Martin
    Blasch, Erik
    [J]. MULTISENSOR, MULTISOURCE INFORMATION FUSION: ARCHITECTURES, ALGORITHMS, AND APPLICATIONS 2007, 2007, 6571
  • [7] Situational Awareness Framework for Cyber Crime Prevention Model in Cyber Physical System
    Joo, Minhee
    Seo, Junwoo
    Oh, Junhyoung
    Park, Mookyu
    Lee, Kyungho
    [J]. 2018 TENTH INTERNATIONAL CONFERENCE ON UBIQUITOUS AND FUTURE NETWORKS (ICUFN 2018), 2018, : 837 - 842
  • [8] Towards a Theoretical Framework for an Active Cyber Situational Awareness Model
    Al-Shamisi, Ahmed
    Louvieris, Panos
    Al-Mualla, Mohammed
    Mihajlov, Martin
    [J]. PROCEEDINGS OF THE 23RD INTERNATIONAL CONFERENCE ON SYSTEMS, SIGNALS AND IMAGE PROCESSING, (IWSSIP 2016), 2016, : 263 - 268
  • [9] A Decision Support Model for Situational Awareness in National Cyber Operations Centers
    Graf, Roman
    Skopik, Florian
    Whitebloom, Kenny
    [J]. 2016 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBERSA), 2016,
  • [10] Phase diagram in multi-phase traffic model
    Nagai, R
    Nagatani, T
    Yamada, A
    [J]. PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2005, 355 (2-4) : 530 - 550