Skip to main navigation Skip to search Skip to main content

Network defense strategy based on cyber attack behavior prediction

  • Wu Ling Ren
  • , Cui Wen Zhao
  • , Guo Xin Jiang
  • , David Maimon
  • , Theodore Wilson
  • , Bertrand Sobesto
  • Zhejiang Gongshang University
  • University of Maryland, College Park

Research output: Contribution to journalArticlepeer-review

4 Scopus citations

Abstract

A network defense strategy based on the prediction of cyber attacker's behaviors was given in order to effectively prevent cyber attacks. Intruders' behaviors have strong randomness and uncertainty. A network of high-interaction honeypots was deployed to collect attack data, especially the behavior data of the attacker after successfully intruding on the host system. By using the attack data, the attack state-transition diagram was generated. Then combining with hidden markov model (HMM) which has fairly precise likelihood probability characteristic, a cyber attacker's behaviors prediction model was designed. With the prediction model and a generally-used intrusion prevention system (IPS), a network defense strategy and its prototype system were proposed. The prototype system was deployed to the real network for attacking test. Through training and verifying with real data over 5 months, the model obtained 80% the prediction accuracy rate. The result shows that the network defense strategy has good network attack confrontation and can be effectively used to prevent cyber attacks.

Original languageEnglish
Pages (from-to)2144-2151 and 2229
JournalZhejiang Daxue Xuebao (Gongxue Ban)/Journal of Zhejiang University (Engineering Science)
Volume48
Issue number12
DOIs
StatePublished - Dec 1 2014

Keywords

  • HMM
  • Honeypot network
  • Intrusion prevention system

Fingerprint

Dive into the research topics of 'Network defense strategy based on cyber attack behavior prediction'. Together they form a unique fingerprint.

Cite this