Skip to main navigation Skip to search Skip to main content

Decepticon: A hidden markov model approach to counter advanced persistent threats

  • SUNY Buffalo

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

5 Scopus citations

Abstract

Deception has been proposed in the literature as an effective defense mechanism to address Advanced Persistent Threats (APT). However, administering deception in a cost-effective manner requires a good understanding of the attack landscape. The attacks mounted by APT groups are highly diverse and sophisticated in nature and can render traditional signature based intrusion detection systems useless. This necessitates the development of behavior oriented defense mechanisms. In this paper, we develop Decepticon (Deception-based countermeasure) a Hidden Markov Model based framework where the indicators of compromise (IoC) are used as the observable features to aid in detection. This framework would help in selecting an appropriate deception script when faced with APTs or other similar malware and trigger an appropriate defensive response. The effectiveness of the model and the associated framework is demonstrated by considering ransomware as the offending APT in a networked system.

Original languageEnglish
Title of host publicationSecure Knowledge Management In Artificial Intelligence Era - 8th International Conference, SKM 2019, Proceedings
EditorsSanjay K. Sahay, Nihita Goel, Vishwas Patil, Murtuza Jadliwala
PublisherSpringer
Pages38-54
Number of pages17
ISBN (Print)9789811538162
DOIs
StatePublished - 2020
Event8th International Conference on Secure Knowledge Management in Artificial Intelligence Era, SKM 2019 - Pilani, India
Duration: Dec 21 2019Dec 22 2019

Publication series

NameCommunications in Computer and Information Science
Volume1186 CCIS
ISSN (Print)1865-0929
ISSN (Electronic)1865-0937

Conference

Conference8th International Conference on Secure Knowledge Management in Artificial Intelligence Era, SKM 2019
Country/TerritoryIndia
CityPilani
Period12/21/1912/22/19

Keywords

  • Advanced Persistent Threats (APT)
  • Computer security
  • Cyber-security
  • Hidden Markov Model (HMM)
  • Ransomware

Fingerprint

Dive into the research topics of 'Decepticon: A hidden markov model approach to counter advanced persistent threats'. Together they form a unique fingerprint.

Cite this