Detecting Network Intrusion Using a Markov Modulated Nonhomogeneous Poisson Process

نویسنده

  • Steven L. Scott
چکیده

Network intrusion occurs when a criminal gains access to a customer's telephone, computer, bank, or other type of account. Detecting network intrusion is an important problem that has received little attention in the statistics literature. This article proposes a Markov modulated nonhomogeneous Poisson process (MMNHPP) to monitor transactions on a customer's account for deviations from the customer's established behavior patterns. An important beneet of the MMNHPP is its ability to model the posterior probability of a criminal presence as a function of time. The MMNHPP combines aspects of the Markov modulated Poisson process and the nonhomogeneous Poisson process to model point processes exhibiting both regular patterns and irregular bursts of activity. The need to accommodate both types of behavior is demonstrated using data from two telephone accounts. MMNHPP parameters are sampled from their posterior distribution given a set of observed event times using an MCMC algorithm. The algorithm switches between drawing missing descriptions of criminal activity given model parameters and sampling model parameters given complete data. An augmented variables scheme is used to render otherwise strongly related elements of the missing data independent in their posterior distribution. Stochastic forward backward recursions for nonstationary hidden Markov models allow the augmenting variables, and thus the entire missing data vector, to be sampled by a single Gibbs step.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Anomaly Detection Using an MMPP-based GLRT

Detection of anomalous network traffic is accomplished using a generalized likelihood ratio test (GLRT) applied to traffic arrival times. The network traffic arrival times are modelled using a Markov modulated Poisson process (MMPP). The GLRT is implemented using an estimate of the MMPP parameter obtained from training data that is not anomalous. MMPP parameter estimation is accomplished using ...

متن کامل

The Markov Modulated Poisson Process and Markov Poisson Cascade with Applications to Web Traffic Modeling

A Markov modulated Poisson Process (MMPP) is a Poisson process whose rate varies according to a Markov process. The nonhomogeneous MMPP developed in this article is a natural model for point processes whose events combine irregular bursts of activity with predictable (e.g. daily and hourly) patterns. We show how the MMPP may be viewed as a superposition of unobserved Poisson processes that are ...

متن کامل

Intrusion Detection Using Evolutionary Hidden Markov Model

Intrusion detection systems are responsible for diagnosing and detecting any unauthorized use of the system, exploitation or destruction, which is able to prevent cyber-attacks using the network package analysis. one of the major challenges in the use of these tools is lack of educational patterns of attacks on the part of the engine analysis; engine failure that caused the complete training,  ...

متن کامل

Traffic Modeling in PLC Networks using a Markov Fluid Model with Autocorrelation Function Fitting

In this paper, we present an analysis of VoIP (Voice over IP) traffic and data transfer using PLC (PowerLine Communications) network. We propose a model based on MMFM (Markov Modulated Fluid Models) for data and VoIP traffic in PLC networks. Simulations and comparisons were carried out to verify the efficiency of the proposed traffic model over the Poisson and MMPP (Markov Modulated Poisson Pro...

متن کامل

Dynamic Analysis of a Unified Multivariate Counting Process and Its Asymptotic Behavior

The class of counting processes constitutes a significant part of applied probability. The classic counting processes include Poisson processes, nonhomogeneous Poisson processes, and renewal processes. More sophisticated counting processes, including Markov renewal processes, Markov modulated Poisson processes, age-dependent counting processes, and the like, have been developed for accommodatin...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2000