Temporal and Stochastic Modelling of Attacker Behaviour

被引:1
|
作者
Rade, Rahul [1 ]
Deshmukh, Soham [1 ]
Nene, Ruturaj [1 ]
Wadekar, Amey S. [1 ]
Unny, Ajay [1 ]
机构
[1] Veermata Jijabai Technol Inst, Mumbai, Maharashtra, India
来源
ADVANCES IN DATA SCIENCE | 2019年 / 941卷
关键词
Cyber security; Threat intelligence; Cowrie honeypot; Markov chain; Hidden Markov Models; Attacker behavioral analysis; Sequence modelling using LSTM;
D O I
10.1007/978-981-13-3582-2_3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber Threat Analysis is one of the emerging focus of information security. Its main functions include identifying the potential threats and predicting the nature of an attacker. Understanding the behaviour of an attacker remains one of the most important aspect of threat analysis, much work has been focused on the detection of concrete network attacks using Intrusion Detection System to raise an alert which subsequently requires human attention. However, we think inspecting the behavioural aspect of an attacker is more intuitive in order to take necessary security measures. In this paper, we propose a novel approach to analyse the behaviour of an attacker in cowrie honeypot. First, we introduce the concept of Honeypot and then model the data using semi-supervised Markov Chains and Hidden Markov Models. We evaluate the suggested methods on a dataset consisting of over a million simulated attacks on a cowrie honeypot system. Along with proposed stochastic models, we also explore the use of Long Short-Term Memory (LSTM) based model for attack sequence modelling. The LSTM based model was found to be better for modelling of long attack sequences as compared to Markov models due to their inability to capture long term dependencies. The results of these models are used to analyse different attack propagation and interaction patterns in the system and predict attacker's next action. These patterns can be used for a better understanding of the existing or evolving attacks and may also aid security experts to comprehend the mindset of an attacker.
引用
收藏
页码:30 / 45
页数:16
相关论文
共 50 条
  • [1] Modelling the stochastic behaviour of primary nucleation
    Maggioni, Giovanni Maria
    Mazzotti, Marco
    FARADAY DISCUSSIONS, 2015, 179 : 359 - 382
  • [2] Stochastic modelling of herd behaviour indices
    Guillaume, Florence
    Linders, Daniel
    QUANTITATIVE FINANCE, 2015, 15 (12) : 1963 - 1977
  • [3] Stochastic modelling of tear behaviour of coated fabrics
    Zhong, W
    Pan, N
    Lukas, D
    MODELLING AND SIMULATION IN MATERIALS SCIENCE AND ENGINEERING, 2004, 12 (02) : 293 - 309
  • [4] Spatio-temporal stochastic modelling (METMAVI)
    Raquel Menezes
    A. Manuela Gonçalves
    Stochastic Environmental Research and Risk Assessment, 2014, 28 : 1167 - 1169
  • [5] Spatio-temporal stochastic modelling (METMAVI)
    Menezes, Raquel
    Manuela Goncalves, A.
    STOCHASTIC ENVIRONMENTAL RESEARCH AND RISK ASSESSMENT, 2014, 28 (05) : 1167 - 1169
  • [6] Modelling temporal behaviour in complex systems with Timebands
    Kun Wei
    Jim Woodcock
    Alan Burns
    Formal Methods in System Design, 2013, 43 : 520 - 551
  • [7] Modelling temporal behaviour in complex systems with Timebands
    Wei, Kun
    Woodcock, Jim
    Burns, Alan
    FORMAL METHODS IN SYSTEM DESIGN, 2013, 43 (03) : 520 - 551
  • [8] Incorporating attacker behavior in stochastic models of security
    Sallhammar, K
    Helvik, BE
    Knapskog, SJ
    SAM '05: Proceedings of the 2005 International Conference on Security and Management, 2005, : 79 - 85
  • [9] On temporal controls and the stochastic behaviour of renewable natural resources
    Batabyal, AA
    RESOURCES POLICY, 2002, 28 (1-2) : 7 - 12
  • [10] Stochastic processes for modelling and evaluating atomic clock behaviour
    Panfilo, G
    Tavella, P
    Zucca, C
    ADVANCED MATHEMATICAL & COMPUTATIONAL TOOLS IN METROLOGY VI, 2004, 66 : 229 - 239