Skip to main content
No Access

Hidden Markov models for advanced persistent threats

Published Online:pp 181-190

Advanced persistent threats (APT) are a serious security risk and tools suited to their detection are needed. These attack campaigns do leave traces in the system, and it is possible to reconstruct part of the attack campaign from these traces. In this article, we describe a hidden Markov model for the evolution of an APT. The aim of this model is to validate whether the evolution of the partially reconstructed attack campaigns are indeed consistent with the evolution of an APT. Since APTs are hard to detect, we also introduce a score to take into account potentially undetected attacks. In addition, the score also allows comparing the fit of APTs of different lengths. We validate and illustrate both the model and the score using data obtained from experts.


intrusion detection, advanced persistent threats, APT, attack campaign, machine learning, hidden Markov models, HMM, score, missing observations, undetected attacks, expert knowledge