4.3 Article

An Effective Reconstruction Method of the APT Attack Based on Hidden Markov Model

期刊

出版社

WORLD SCIENTIFIC PUBL CO PTE LTD
DOI: 10.1142/S0218126622501080

关键词

APT; hidden Markov model; APT attack reconstruction

资金

  1. Research Innovation Fund for College Students of Beijing University of Posts and Telecommunications [202111018, 202103024]

向作者/读者索取更多资源

This paper introduces a method for reconstructing APT attack scenes. By mining hidden attack events, describing action sequences, and reconstructing attack paths, the detection of APT attack processes and the reconstruction of attack scenes are achieved.
Advanced Persistent Threat (APT) is a multi-stage and multi-step attack process. The reconstruction of the APT attack scene can start with discrete stage attack detection. However, due to the strong characteristic of concealment of APT attacks, some discrete events in the attack scenarios may not be detected. Therefore, to reconstruct the APT attack scene, we need to mine the hidden attack events according to the APT attack target and the detected discrete attack events, describe the action sequence according to the time sequence or the conditions reached by the attack, and finally reconstruct the attack path. In this paper, we depend on the EP-IKC attack cooperation model, we take the total target of APT attack as the pyramid vertex, and the alerted network entities and potential attacked entities related to the vertex as the facet nodes, this paper introduces the hidden Markov model (HMM), and uses the methods of data association and advanced probability theory to mine the hidden APT attack stages, Finally, the detection of APT attack process and the reconstruction of attack scene are realized.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.3
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据