Security Metric Methods for Network Multistep Attacks Using AMC and Big Data Correlation Analysis

المؤلفون المشاركون

Zhang, Yuchen
Hu, Hao
Zhang, Hongqi
Liu, Yuling

المصدر

Security and Communication Networks

العدد

المجلد 2018، العدد 2018 (31 ديسمبر/كانون الأول 2018)، ص ص. 1-14، 14ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2018-08-02

دولة النشر

مصر

عدد الصفحات

14

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

Network security metrics allow quantitatively evaluating the overall resilience of networked systems against attacks.

From this aim, security metrics are of great importance to the security-related decision-making process of enterprises.

In this paper, we employ absorbing Markov chain (AMC) to estimate the network security combining with the technique of big data correlation analysis.

Specifically, we construct the model of AMC using a large amount of alert data to describe the scenario of multistep attacks in the real world.

In addition, we implement big data correlation analysis to generate the transition probability matrix from alert stream, which defines the probabilities of transferring from one attack action to another according to a given scenario before reaching one of some attack targets.

Based on the probability reasoning, two metric algorithms are designed to estimate the attack scenario as well as the attackers, namely, the expected number of visits (ENV) and the expected success probability (ESP).

The superiority is that the proposed model and algorithms assist the administrator in building new scenarios, prioritizing alerts, and ranking them.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Hu, Hao& Liu, Yuling& Zhang, Hongqi& Zhang, Yuchen. 2018. Security Metric Methods for Network Multistep Attacks Using AMC and Big Data Correlation Analysis. Security and Communication Networks،Vol. 2018, no. 2018, pp.1-14.
https://search.emarefa.net/detail/BIM-1214237

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Hu, Hao…[et al.]. Security Metric Methods for Network Multistep Attacks Using AMC and Big Data Correlation Analysis. Security and Communication Networks No. 2018 (2018), pp.1-14.
https://search.emarefa.net/detail/BIM-1214237

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Hu, Hao& Liu, Yuling& Zhang, Hongqi& Zhang, Yuchen. Security Metric Methods for Network Multistep Attacks Using AMC and Big Data Correlation Analysis. Security and Communication Networks. 2018. Vol. 2018, no. 2018, pp.1-14.
https://search.emarefa.net/detail/BIM-1214237

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1214237