Sie befinden Sich nicht im Netzwerk der Universität Paderborn. Der Zugriff auf elektronische Ressourcen ist gegebenenfalls nur via VPN oder Shibboleth (DFN-AAI) möglich. mehr Informationen...
PloS one, 2024-03, Vol.19 (3), p.e0300821-e0300821
2024

Details

Autor(en) / Beteiligte
Titel
Anomaly based multi-stage attack detection method
Ist Teil von
  • PloS one, 2024-03, Vol.19 (3), p.e0300821-e0300821
Ort / Verlag
United States: Public Library of Science
Erscheinungsjahr
2024
Link zum Volltext
Quelle
MEDLINE
Beschreibungen/Notizen
  • Multi-stage attacks are one of the most critical security threats in the current cyberspace. To accurately identify multi-stage attacks, this paper proposes an anomaly-based multi-stage attack detection method. It constructs a Multi-Stage Profile (MSP) by modeling the stable system's normal state to detect attack behaviors. Initially, the method employs Doc2Vec to vectorize alert messages generated by the intrusion detection systems (IDS), extracting profound inter-message correlations. Subsequently, Hidden Markov Models (HMM) are employed to model the normal system state, constructing an MSP, with relevant HMM parameters dynamically acquired via clustering algorithms. Finally, the detection of attacks is achieved by determining the anomaly threshold through the generation probability (GP). To evaluate the performance of the proposed method, experiments were conducted using three public datasets and compared with three advanced multi-stage attack detection methods. The experimental results demonstrate that our method achieves an accuracy of over 99% and precision of 100% in multi-stage attack detection. This confirms the effectiveness of our method in adapting to different attack scenarios and ultimately completing attack detection.
Sprache
Englisch
Identifikatoren
ISSN: 1932-6203
eISSN: 1932-6203
DOI: 10.1371/journal.pone.0300821
Titel-ID: cdi_doaj_primary_oai_doaj_org_article_a415451d5edf4493840783461c393755

Weiterführende Literatur

Empfehlungen zum selben Thema automatisch vorgeschlagen von bX