Computer and Modernization

Previous Articles     Next Articles

CyberSecuritySituationEvaluationMethodBasedon#br# AssociationAnalysisandHiddenMarkovModel

  

  1. (SchoolofAutomation,NanjingUniversityofScienceandTechnology,Nanjing210094,China)
  • Received:2017-12-19 Online:2018-07-05 Published:2018-07-05

Abstract: MostofthecurrentnetworksecuritysituationassessmentmethodsbasedonHMMarefocusedonthestudyofHMMparameters,ignoringtheimpactofobservationvaluesonevaluationaccuracy.Thispaperisbasedontheaggregationofalarminformation,takesattackmodeasabasisforassociation,combinesthevulnerabilityinformationofnetworkassets,identifiestheattackphaseofthehostandconvertsittothethreatlevelofthehost,andfinally,usesHMMtoevaluatethesecuritysituationofthehostandnetwork.ExperimentbasedonDARPA2000datasetshows,comparedwiththegeneralHMMmethod,thismethodcanreflectthemulti-stepcharacteristicsoftheattack,anditcanmoreaccuratelyreflectthechangeofnetworksituation.

Key words: multi-stepattackspattern, associationanalysis, hiddenMarkovmodel, cybersecuritysituationevaluation

CLC Number: