Publicación: Detección temprana de ataques cibernéticos avanzados (APT) mediante modelos ocultos de Markov aplicados al análisis de comportamientos en sistemas de seguridad
Portada
Citas bibliográficas
Código QR
Autores
Director
Fecha
Resumen en español
Las amenazas persistentes avanzadas, conocidas por su sigla en inglés APT, pertenecen a los problemas de seguridad más difíciles de resolver para las organizaciones colombianas. A diferencia de los ataques convencionales, que buscan un efecto rápido y más fácil de detectar, las APT operan durante semanas o meses dentro de los sistemas comprometidos sin disparar ninguna alerta. Cuando finalmente son descubiertas, el daño acumulado suele ser irreversible. Los métodos de detección vigentes los cuales están basados en bases de firmas maliciosas conocidas o en reglas estáticas predefinidas, procesan cada evento de seguridad de manera independiente y son incapaces de leer el significado que emerge cuando esos eventos se encadenan en el tiempo. El presente proyecto responde a esa limitación con un sistema de detección temprana construido sobre modelos ocultos de Márkov (HMM) de arquitectura jerárquica, entrenado sobre secuencias de eventos reales provenientes de los datasets DARPA Transparent Computing, LANL y cierto grupo de logs extraídos de un ataque simulado usando máquinas virtuales Windows y Linux. El modelo infiere probabilísticamente la fase del ciclo de vida del ataque en que opera el adversario, produce alertas progresivas integradas en Elastic Stack y supera, en precisión, recall, F1-score, a métodos de referencia Random Forest y redes LSTM. Los hallazgos esperados confirman la viabilidad del enfoque para su aplicación en organizaciones que carecen de soluciones comerciales de alto costo (Centro Cibernético Policial, 2024, secc. “Cifras generales”; IBM Security, 2024, p. 8; Rabiner, 1989, p. 258; Ghafir et al., 2019, p. 99510).
Resumen en inglés
Advanced Persistent Threats (APTs) are among the most difficult cybersecurity challenges faced by organizations in Colombia. Unlike conventional cyberattacks, which are often designed to cause immediate and noticeable effects, APTs can remain hidden inside compromised systems for weeks or even months without being detected. During this time, attackers are able to carry out malicious activities while avoiding security controls. As a result, when the attack is finally discovered, the damage is often significant and difficult to undo. Most current detection methods rely on known malware signatures or predefined security rules. While these approaches can identify familiar threats, they usually examine security events separately and therefore have difficulty recognizing the patterns that emerge when multiple events are linked over time. This limitation makes it harder to detect sophisticated attacks that unfold gradually and in several stages. To address this problem, this project proposes an early detection system based on hierarchical Hidden Markov Models (HMMs), the model is trained using real-world event data from the DARPA Transparent Computing and Los Alamos National Laboratory (LANL) datasets, as well as logs generated from a controlled simulation of an APT attack carried out in virtualized Windows and Linux environments. By analyzing sequences of events, the system estimates the stage of the attack being carried out and generates progressive alerts through the Elastic Stack platform. Its performance is evaluated using precision, recall, and F1- score and compared with well-known approaches such as Random Forest and Long ShortTerm Memory (LSTM) Networks, the expected results seek to demonstrate that this approach can provide an effective and affordable alternative for organizations that do not have access to high-cost commercial cybersecurity solutions (Centro Cibernético Policial, 2024, secc. “Cifras generales”; IBM Security, 2024, p. 8; Rabiner, 1989, p. 258; Ghafir et al., 2019, p. 99510).

PDF
FLIP 
