Detecting Trajectory of Targeted Attack by Hidden Markov Model
摘要
The proliferation of the internet has accelerated information transmission, greatly facilitating everyday life. However, with increasing digitalization, cyberattacks have become more prevalent and sophisticated, intensifying information security challenges. Modern attack techniques have evolved from random intrusions to precise, targeted assaults on governmental and enterprise systems, with Advanced Persistent Threats (APTs) being a prominent example. These targeted attacks often remain undetected for long periods, lying dormant until the optimal moment to strike, thereby causing substantial damage before detection. Based on real-world cyberattack data, this study identifies that attack behaviors exhibit observable patterns before initiation. To capture these latent behavioral transitions, we propose a hybrid Elastic Net–HMM framework. The Elastic Net model isolates critical and sparse attack features, which are then used as the observation vectors for a Hidden Markov Model (HMM) to infer state transitions. Unlike conventional non-sequential intrusion detection models that rely on the i.i.d. assumption and thus fail to model temporal dependencies, the proposed approach integrates feature selection and sequential modeling to improve interpretability and early-stage detection. Experimental evaluation demonstrates that the proposed framework achieves a detection rate of 94.71% and a recall of 92.86%, outperforming baseline non-sequential models (best recall = 64.28%) by 28.58 percentage points (approximately 44.5% relative improvement). This approach significantly enhances the precision of network security monitoring and provides earlier risk interpretation with low false positives. The findings highlight its strong applicability for deployment in enterprise Security Operation Centers (SOCs) as an early-warning module for APT detection, thereby strengthening real-time cyber defense in increasingly complex threat environments.