TY - GEN
T1 - A novel stochastic modeling method for network security situational awareness
AU - Liang, Y.
AU - Wang, H. Q.
AU - Cai, H. B.
AU - He, Y. J.
PY - 2008
Y1 - 2008
N2 - Hidden Markov Model (HMM) is used to model network security situational awareness (NSA). Distribution of abnormal behaviors in networked system and operational states of key network services are abstracted by Markov chains, modeling objects of the HMM's dual stochastic processes are set up, and classic Baum-Welch algorithm is used to estimate the parameters of the established stochastic mathematical model, then the stochastic modeling for network security situational awareness based upon HMM is realized. The simulation experimental results in LAN show that the model can effectively analyze and validate network security situation, and it is a novel attempt in achieving network security situational awareness, which prompts the development of theoretical researches in the field of NSA at a certain degree.
AB - Hidden Markov Model (HMM) is used to model network security situational awareness (NSA). Distribution of abnormal behaviors in networked system and operational states of key network services are abstracted by Markov chains, modeling objects of the HMM's dual stochastic processes are set up, and classic Baum-Welch algorithm is used to estimate the parameters of the established stochastic mathematical model, then the stochastic modeling for network security situational awareness based upon HMM is realized. The simulation experimental results in LAN show that the model can effectively analyze and validate network security situation, and it is a novel attempt in achieving network security situational awareness, which prompts the development of theoretical researches in the field of NSA at a certain degree.
UR - https://www.scopus.com/pages/publications/51949084082
U2 - 10.1109/ICIEA.2008.4582951
DO - 10.1109/ICIEA.2008.4582951
M3 - 会议稿件
AN - SCOPUS:51949084082
SN - 9781424417186
T3 - 2008 3rd IEEE Conference on Industrial Electronics and Applications, ICIEA 2008
SP - 2422
EP - 2426
BT - 2008 3rd IEEE Conference on Industrial Electronics and Applications, ICIEA 2008
T2 - 2008 3rd IEEE Conference on Industrial Electronics and Applications, ICIEA 2008
Y2 - 3 June 2008 through 5 June 2008
ER -