Paper Title: Probabilistic-temporal modeling of network security monitoring subprocesses for multi-stage attacks in IoT networks
Authors: Ammar Dawood Jasim, Mokhalad Al-Tameemi
Corresponding Author: Ammar Dawood Jasim (Ammar.alaythawy@nahrainuniv.edu.iq)/Iraq
Abstract
Timely detection of a multistage cyberattack in an IoT network depends on the chosen monitoring architecture, execution time, and the transition behavior of subprocesses within that architecture. This paper introduces a probabilistic temporal model to evaluate an NSMS for both known and unknown multi-stage attacks. First, we introduce a conceptual monitoring architecture that organizes streaming-data processing, temporal analysis, attack classification, attack prediction, and response selection. The recurrent neural networks in the architecture form the basis of the implementation framework and are neither trained nor empirically analyzed. The evaluated contribution represents the NSMS subprocesses as a continuous-time Markov chain, where each state corresponds to a monitoring task and each transition rate is estimated from the respective mean processing time. We develop state-probability equations and use a specialized software tool to estimate the stationary probabilities and successful anomaly-detection probabilities. Numerical evaluations examine how delays in preprocessing, syntactic construction, encoding, classification, and prediction affect monitoring effectiveness. The analysis shows that the estimated probability of successful anomaly detection decreases as preprocessing and encoding time increases, underscoring the need to account for computational delay in time-critical security monitoring. The sensitivity and steady-state analyses identify the subprocesses that most affect the modeled system’s behavior. The developed framework enables quantitative evaluation of NSMS timing constraints and allocation of computational resources before designing and experimentally evaluating the learning-based architecture.