Title :
A novel hidden Markov model for detecting complicate network attacks
Author :
Zhicai, Shi ; Yongxiang, Xia
Author_Institution :
Electron. & Electr. Eng. Inst., Shanghai Univ. of Eng. Sci., Shanghai, China
Abstract :
It is difficult to detect complicate network attacks effectively nowadays. To detect these attacks the inherent characteristics of complicate network attacks are analyzed in detail. A novel hidden Markov model is proposed. The model is composed of several different monitors. In order to simplify the training procedure of the model and to improve its response performance warning events are classified into different types at first. Then the sequences of warning event types from different network monitors are correlated and their inherent relationship is mined so as to detect the type of complicate network attacks and to forecast their threat degree to the system. The experimental results show that the proposed model could recognize complicate network attacks effectively.
Keywords :
Computer crime; Error analysis; Event detection; Hidden Markov models; Information security; Information systems; Intrusion detection; Pattern analysis; Performance analysis; Probability distribution; hidden Markov model; intrusion detection; network; network attacks;
Conference_Titel :
Wireless Communications, Networking and Information Security (WCNIS), 2010 IEEE International Conference on
Conference_Location :
Beijing, China
Print_ISBN :
978-1-4244-5850-9
DOI :
10.1109/WCINS.2010.5541790