I-HMM-Based Multidimensional Network Security Risk Assessment

Cyber-physical systems (CPS) are vulnerable to network attacks because communication relies on the network that links the various components in the CPS. The importance of network security is self-evident. In this study, we conduct a network security risk assessment from the perspectives of the host...

Full description

Bibliographic Details
Main Authors: Jingjing Hu, Shuangshuang Guo, Xiaohui Kuang, Fankun Meng, Dongsheng Hu, Zhiyu Shi
Format: Article
Language:English
Published: IEEE 2020-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/8941077/
id doaj-fe0c4ee1a0f047a6994a8e81b43f6d80
record_format Article
spelling doaj-fe0c4ee1a0f047a6994a8e81b43f6d802021-03-30T02:48:27ZengIEEEIEEE Access2169-35362020-01-0181431144210.1109/ACCESS.2019.29619978941077I-HMM-Based Multidimensional Network Security Risk AssessmentJingjing Hu0https://orcid.org/0000-0002-3220-621XShuangshuang Guo1https://orcid.org/0000-0001-9971-1037Xiaohui Kuang2https://orcid.org/0000-0003-3816-402XFankun Meng3https://orcid.org/0000-0003-2465-743XDongsheng Hu4https://orcid.org/0000-0003-1740-3319Zhiyu Shi5https://orcid.org/0000-0003-2732-6249School of Computer Science and Technology, Beijing Institute of Technology, Beijing, ChinaSchool of Computer Science and Technology, Beijing Institute of Technology, Beijing, ChinaNational Key Laboratory of Science and Technology on Information System Security, Beijing, ChinaSchool of Computer Science and Technology, Beijing Institute of Technology, Beijing, ChinaSchool of Computer Science and Technology, Beijing Institute of Technology, Beijing, ChinaSchool of Computer Science and Technology, Beijing Institute of Technology, Beijing, ChinaCyber-physical systems (CPS) are vulnerable to network attacks because communication relies on the network that links the various components in the CPS. The importance of network security is self-evident. In this study, we conduct a network security risk assessment from the perspectives of the host and the network, and we propose a new framework for a multidimensional network security risk assessment that includes two stages, i.e., risk identification and risk calculation. For the risk identification stage, we propose a multidimensional hierarchical index system for assessing cybersecurity risk; the system's security status is determined in three dimensions, i.e., basic operation, vulnerabilities, and threats, and these dimensions guide the data collection. In the risk calculation stage, we use a hidden Markov model (HMM) to assess the network security risk. We provide a new definition of the quality of alert and optimize the observation sequence of the HMM. The model uses a learning algorithm instead of setting the parameters manually. We introduce the concept of network node association to increase the reliability and accuracy of the risk assessment. The simulation results show that the proposed index system provides quantitative data that reflect the security status of the network. The proposed network security risk assessment method based on the improved HMM (I-HMM) reflects the security risk status in a timely and intuitive manner and detects the degree of risk that different hosts pose to the network.https://ieeexplore.ieee.org/document/8941077/Hidden Markov modelnetwork node correlationnetwork security riskrisk assessment
collection DOAJ
language English
format Article
sources DOAJ
author Jingjing Hu
Shuangshuang Guo
Xiaohui Kuang
Fankun Meng
Dongsheng Hu
Zhiyu Shi
spellingShingle Jingjing Hu
Shuangshuang Guo
Xiaohui Kuang
Fankun Meng
Dongsheng Hu
Zhiyu Shi
I-HMM-Based Multidimensional Network Security Risk Assessment
IEEE Access
Hidden Markov model
network node correlation
network security risk
risk assessment
author_facet Jingjing Hu
Shuangshuang Guo
Xiaohui Kuang
Fankun Meng
Dongsheng Hu
Zhiyu Shi
author_sort Jingjing Hu
title I-HMM-Based Multidimensional Network Security Risk Assessment
title_short I-HMM-Based Multidimensional Network Security Risk Assessment
title_full I-HMM-Based Multidimensional Network Security Risk Assessment
title_fullStr I-HMM-Based Multidimensional Network Security Risk Assessment
title_full_unstemmed I-HMM-Based Multidimensional Network Security Risk Assessment
title_sort i-hmm-based multidimensional network security risk assessment
publisher IEEE
series IEEE Access
issn 2169-3536
publishDate 2020-01-01
description Cyber-physical systems (CPS) are vulnerable to network attacks because communication relies on the network that links the various components in the CPS. The importance of network security is self-evident. In this study, we conduct a network security risk assessment from the perspectives of the host and the network, and we propose a new framework for a multidimensional network security risk assessment that includes two stages, i.e., risk identification and risk calculation. For the risk identification stage, we propose a multidimensional hierarchical index system for assessing cybersecurity risk; the system's security status is determined in three dimensions, i.e., basic operation, vulnerabilities, and threats, and these dimensions guide the data collection. In the risk calculation stage, we use a hidden Markov model (HMM) to assess the network security risk. We provide a new definition of the quality of alert and optimize the observation sequence of the HMM. The model uses a learning algorithm instead of setting the parameters manually. We introduce the concept of network node association to increase the reliability and accuracy of the risk assessment. The simulation results show that the proposed index system provides quantitative data that reflect the security status of the network. The proposed network security risk assessment method based on the improved HMM (I-HMM) reflects the security risk status in a timely and intuitive manner and detects the degree of risk that different hosts pose to the network.
topic Hidden Markov model
network node correlation
network security risk
risk assessment
url https://ieeexplore.ieee.org/document/8941077/
work_keys_str_mv AT jingjinghu ihmmbasedmultidimensionalnetworksecurityriskassessment
AT shuangshuangguo ihmmbasedmultidimensionalnetworksecurityriskassessment
AT xiaohuikuang ihmmbasedmultidimensionalnetworksecurityriskassessment
AT fankunmeng ihmmbasedmultidimensionalnetworksecurityriskassessment
AT dongshenghu ihmmbasedmultidimensionalnetworksecurityriskassessment
AT zhiyushi ihmmbasedmultidimensionalnetworksecurityriskassessment
_version_ 1724184585129951232