|
Short communications
Hidden Markov model for malicious hosts detection in a computer network
Ya. V. Bubnov, N. N. Ivanov Belarusian State University of Informatics and Radioelectronics,
6 Pietrusia Broŭki Street, Minsk 220013, Belarus
Abstract:
The problem of malicious host detection in a computer network is reviewed. Activity of computer network hosts is tracking by a noisy detector. The paper suggests method for detection malicious hosts using activity timeseries classification. The approach is based on hidden Markov chain model that analyses timeseries and consecutive search of the most probable final state of the model. Efficiency of the approach is based on assumption that advanced persisted threats are localised in time, therefore malicious hosts in a computer network can be detected by virtue of activity comparison with reliable safe hosts.
Keywords:
hidden Markov model; computer network; advanced persisted threat; timeseries classification.
Received: 29.06.2020
Citation:
Ya. V. Bubnov, N. N. Ivanov, “Hidden Markov model for malicious hosts detection in a computer network”, Journal of the Belarusian State University. Mathematics and Informatics, 3 (2020), 73–79
Linking options:
https://www.mathnet.ru/eng/bgumi85 https://www.mathnet.ru/eng/bgumi/v3/p73
|
Statistics & downloads: |
Abstract page: | 53 | Full-text PDF : | 64 | References: | 15 |
|