Skip to search boxSkip to navigationSkip to main content

Intrusion activity projection for cyber situational awareness

  • Rochester Institute of Technology
    ,
  • University of Buffalo
Research Output:
Contribution to conference
Paper
Peer-review

Abstract

Previous works in the area of network security have emphasized the creation of Intrusion Detection Systems (IDSs) to flag malicious network traffic and computer usage. Raw IDS data may be correlated and form attack tracks, each of which consists of ordered collections of alerts belonging to a single multi-stage attack. Assessing an attack track in its early stage may reveal the attacker's capability and behavior trends, leading to projections of future intrusion activities. Behavior trends are captured via Variable Length Markov Models (VLMM) without predetermined attack plans. A virtual terrain schema is developed to model network and system configurations, and used to estimate critical elements and vulnerabilities exposed to each attacker given his/her progress. Experimental results show promises for these proactive measures in ensuring continuous and critical cyber operations.

Bibliographic Information

Output type

Research Output:
Contribution to conference
Paper
Peer-review

Original language

English

Pages from-to (Number of pages)

Pages 167-172 (6 pages)

Publication milestones

  • Published - 2008

Publication status

Published - 2008

Publication IDs

  • Scopus: 51849103254