A Hidden Markov Model Based Framework for Tracking and Predicting of Attack Intention

Xin Zan,Feng Gao,Jiuqiang Han,Yu Sun
DOI: https://doi.org/10.1109/mines.2009.277
2009-01-01
Abstract:Recently, several approaches for intrusion correlation and attack scenario analysis have been proposed. However, these approaches all focus on the flooding alert reduction or high-level alert correlation. In this paper, we study the problem of tracking and predicting of attack intentions. We use hidden markov models to represent the typical attack scenarios and design a complete framework named HMM-AIP composed of online tracking and prediction module and offline model training module. A novel and effective tracking and predicting attack intention algorithm is presented. We perform experiments to validate our algorithm and the results show that our approach can identify false alert and give the creditable prediction result when the alert observation sequence fits the typical attack scenarios nicely.
What problem does this paper attempt to address?