Abstract
A network defense strategy based on the prediction of cyber attacker's behaviors was given in order to effectively prevent cyber attacks. Intruders' behaviors have strong randomness and uncertainty. A network of high-interaction honeypots was deployed to collect attack data, especially the behavior data of the attacker after successfully intruding on the host system. By using the attack data, the attack state-transition diagram was generated. Then combining with hidden markov model (HMM) which has fairly precise likelihood probability characteristic, a cyber attacker's behaviors prediction model was designed. With the prediction model and a generally-used intrusion prevention system (IPS), a network defense strategy and its prototype system were proposed. The prototype system was deployed to the real network for attacking test. Through training and verifying with real data over 5 months, the model obtained 80% the prediction accuracy rate. The result shows that the network defense strategy has good network attack confrontation and can be effectively used to prevent cyber attacks.
| Original language | English |
|---|---|
| Pages (from-to) | 2144-2151 and 2229 |
| Journal | Zhejiang Daxue Xuebao (Gongxue Ban)/Journal of Zhejiang University (Engineering Science) |
| Volume | 48 |
| Issue number | 12 |
| DOIs | |
| State | Published - Dec 1 2014 |
Keywords
- HMM
- Honeypot network
- Intrusion prevention system
Fingerprint
Dive into the research topics of 'Network defense strategy based on cyber attack behavior prediction'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver