Modeling Malicious Network Packets with Generative Probabilistic Graphical Models

نویسنده

  • Ashe Magalhaes
چکیده

Cyber enterprise systems often are difficult to protect due to a large number of sub-components that must work in concert to remain resilient. In cyber enterprises where incoming traffic may approach a few megabits per second, an IDS and host system controlled by a Markov Decision Process may serve as an efficient resiliency solution. However, the structure of this model leverages very little information about the adversary. For example, attack signatures of well known attacks and the behavior of previous packets are not considered when the system decides if a network packet is malicious or normal. In this paper, we attempt a first step to augmenting such a resiliency system by learning about adversary behavior through modeling malicious packet data with a probabilistic graphical model. We examine the effects of weakening the Markov assumption on the behavior of an adversary, and investigate how well this Markov adversary model is borne out in real data for four different cyber attack types. Finally, we investigate how well our model captures intrinsic characteristics of malicious behavior by using log-likelihood scores of various attack models to train a discriminative classifier; we find that our classifier is able to attain anywhere from 93% to 98% classification accuracy, a strong indicator that our generative models have successfully captured the distribution of features and behaviors that comprise a malicious adversary vs. a benign one.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Rule-based joint fuzzy and probabilistic networks

One of the important challenges in Graphical models is the problem of dealing with the uncertainties in the problem. Among graphical networks, fuzzy cognitive map is only capable of modeling fuzzy uncertainty and the Bayesian network is only capable of modeling probabilistic uncertainty. In many real issues, we are faced with both fuzzy and probabilistic uncertainties. In these cases, the propo...

متن کامل

A Logic-based Approach to Generatively Defined Discriminative Modeling

Conditional random fields (CRFs) are usually specified by graphical models but in this paper we propose to use probabilistic logic programs and specify them generatively. Our intension is first to provide a unified approach to CRFs for complex modeling through the use of a Turing complete language and second to offer a convenient way of realizing generative-discriminative pairs in machine learn...

متن کامل

Probabilistic Language Modeling with Hidden Stochastic Automata

In this paper, we introduce a novel dynamical Bayesian network model for probabilistic language modeling. We refer to this as the Hidden Stochastic Automaton. This model, while based on a generalization of the Hidden Markov model, has qualitatively greater generative power than either the Hidden Markov model itself or any of its existing variants and generalizations. This allows the Hidden Stoc...

متن کامل

Introduction to Probabilistic Graphical Models

Over the last decades, probabilistic graphical models have become the method of choice for representing uncertainty in machine learning. They are used in many research areas such as computer vision, speech processing, time-series and sequential data modelling, cognitive science, bioinformatics, probabilistic robotics, signal processing, communications and error-correcting coding theory, and in ...

متن کامل

Probabilistic Models and Generative Neural Networks: Towards an Unified Framework for Modeling Normal and Impaired Neurocognitive Functions

Connectionist models can be characterized within the more general framework of probabilistic graphical models, which allow to efficiently describe complex statistical distributions involving a large number of interacting variables. This integration allows building more realistic computational models of cognitive functions, which more faithfully reflect the underlying neural mechanisms at the sa...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2016