Security Metric Methods for Network Multistep Attacks Using AMC and Big Data Correlation Analysis

Joint Authors

Zhang, Yuchen
Hu, Hao
Zhang, Hongqi
Liu, Yuling

Source

Security and Communication Networks

Issue

Vol. 2018, Issue 2018 (31 Dec. 2018), pp.1-14, 14 p.

Publisher

Hindawi Publishing Corporation

Publication Date

2018-08-02

Country of Publication

Egypt

No. of Pages

14

Main Subjects

Information Technology and Computer Science

Abstract EN

Network security metrics allow quantitatively evaluating the overall resilience of networked systems against attacks.

From this aim, security metrics are of great importance to the security-related decision-making process of enterprises.

In this paper, we employ absorbing Markov chain (AMC) to estimate the network security combining with the technique of big data correlation analysis.

Specifically, we construct the model of AMC using a large amount of alert data to describe the scenario of multistep attacks in the real world.

In addition, we implement big data correlation analysis to generate the transition probability matrix from alert stream, which defines the probabilities of transferring from one attack action to another according to a given scenario before reaching one of some attack targets.

Based on the probability reasoning, two metric algorithms are designed to estimate the attack scenario as well as the attackers, namely, the expected number of visits (ENV) and the expected success probability (ESP).

The superiority is that the proposed model and algorithms assist the administrator in building new scenarios, prioritizing alerts, and ranking them.

American Psychological Association (APA)

Hu, Hao& Liu, Yuling& Zhang, Hongqi& Zhang, Yuchen. 2018. Security Metric Methods for Network Multistep Attacks Using AMC and Big Data Correlation Analysis. Security and Communication Networks،Vol. 2018, no. 2018, pp.1-14.
https://search.emarefa.net/detail/BIM-1214237

Modern Language Association (MLA)

Hu, Hao…[et al.]. Security Metric Methods for Network Multistep Attacks Using AMC and Big Data Correlation Analysis. Security and Communication Networks No. 2018 (2018), pp.1-14.
https://search.emarefa.net/detail/BIM-1214237

American Medical Association (AMA)

Hu, Hao& Liu, Yuling& Zhang, Hongqi& Zhang, Yuchen. Security Metric Methods for Network Multistep Attacks Using AMC and Big Data Correlation Analysis. Security and Communication Networks. 2018. Vol. 2018, no. 2018, pp.1-14.
https://search.emarefa.net/detail/BIM-1214237

Data Type

Journal Articles

Language

English

Notes

Includes bibliographical references

Record ID

BIM-1214237