Real-time Risk Assessment Based on Hidden Markov Model and Security Configuration

Ding Yu-Ting,Qu Hai-Peng,Teng Xi-Long
DOI: https://doi.org/10.1109/infoseee.2014.6946191
2014-01-01
Abstract:Most of the existing risk assessment methods are generally limited to external factors and ignore internal factors. Here we introduce a real-time method to network risk assessment that takes both external and internal factors into consideration. First, we apply intrusion detection system and configuration verification system to detect external and internal threats respectively. Then, to speculate system changes, a matrix that combines external and internal threats is added to hidden Markov models. Finally, new state transition probability matrices are automatically generated based on the changes, which remedies the deficiency of static transition matrix in the original models. Experimental results show that the improved algorithm can improve the accuracy and reliability of assessment results.
What problem does this paper attempt to address?