Main Article Content

Abstract

Timely detection of a multistage cyberattack in an IoT network depends on the chosen monitoring architecture, execution time, and the transition behavior of subprocesses within that architecture. This paper introduces a probabilistic temporal model to evaluate an NSMS for both known and unknown multi-stage attacks. First, we introduce a conceptual monitoring architecture that organizes streaming-data processing, temporal analysis, attack classification, attack prediction, and response selection. The recurrent neural networks in the architecture form the basis of the implementation framework and are neither trained nor empirically analyzed. The evaluated contribution represents the NSMS subprocesses as a continuous-time Markov chain, where each state corresponds to a monitoring task and each transition rate is estimated from the respective mean processing time. We develop state-probability equations and use a specialized software tool to estimate the stationary probabilities and successful anomaly-detection probabilities. Numerical evaluations examine how delays in preprocessing, syntactic construction, encoding, classification, and prediction affect monitoring effectiveness. The analysis shows that the estimated probability of successful anomaly detection decreases as preprocessing and encoding time increases, underscoring the need to account for computational delay in time-critical security monitoring. The sensitivity and steady-state analyses identify the subprocesses that most affect the modeled system's behavior. The developed framework enables quantitative evaluation of NSMS timing constraints and allocation of computational resources before designing and experimentally evaluating the learning-based architecture.

Keywords

Internet of Things Network security monitoring Recurrent neural networks Multi-stage attacks Anomaly detection

Article Details

How to Cite
Dawood Jasim, A., & Al-Tameemi, M. . (2026). Probabilistic-temporal modeling of network security monitoring subprocesses for multi-stage attacks in IoT networks. Future Technology, 5(4), 257–269. Retrieved from https://fupubco.com/futech/article/view/1149
Bookmark and Share

References

  1. N. Kalpani, N. Rodrigo, D. Seneviratne, et al., “Resilient cybersecurity: Ensemble deep learning and reinforcement learning for Next-Gen IDS,” Iran Journal of Computer Science, vol. 9, Art. no. 19, 2026, doi: 10.1007/s42044-025-00364-3.
  2. K. Zhao, Z. Zhang, Z. Liang, Z. Zhang and G. Quan, "Bi-NLSTM: A Multi-Stage Attack Detection Approach for Industrial Internet," in Chinese Journal of Electronics, vol. 35, no. 2, pp. 713-724, March 2026, doi: 10.23919/cje.2025.00.254.
  3. X. Li, M. Xu, P. Vijayakumar, N. Kumar, and X. Liu, “Detection of low-frequency and multi-stage attacks in industrial Internet of Things,” IEEE Transactions on Vehicular Technology, vol. 69, no. 8, pp. 8820–8831, 2020, doi: 10.1109/TVT.2020.2995133.
  4. A. Pinto, L. C. Herrera, Y. Donoso, and J. A. Gutierrez, “Survey on intrusion detection systems based on machine learning techniques for the protection of critical infrastructure,” Sensors, vol. 23, no. 5, Art. no. 2415, 2023, doi: 10.3390/s23052415.
  5. P. Zhou, G. Zhou, D. Wu, and M. Fei, “Detecting multi-stage attacks using sequence-to-sequence model,” Computers & Security, vol. 105, Art. no. 102203, 2021, doi: 10.1016/j.cose.2021.102203.
  6. S. Mishra, W. B. Alotaibi, M. Alshehri, and S. Saxena, “Cyber-attacks visualisation and prediction in complex multi-stage network,” International Journal of Computer Applications in Technology, vol. 68, no. 4, pp. 345–356, 2022, doi: 10.1504/IJCAT.2022.125180.
  7. P. B. Weerakody, K. W. Wong, G. Wang, and W. Ela, “A review of irregular time series data handling with gated recurrent neural networks,” Neurocomputing, vol. 441, pp. 161–178, 2021, doi: 10.1016/j.neucom.2021.02.046.
  8. M. A. Khan, “HCRNNIDS: Hybrid convolutional recurrent neural network-based network intrusion detection system,” Processes, vol. 9, no. 5, Art. no. 834, 2021, doi: 10.3390/pr9050834.
  9. I. Al-Turaiki and N. Altwaijry, “A convolutional neural network for improved anomaly-based network intrusion detection,” Big Data, vol. 9, no. 3, pp. 233–252, 2021, doi: 10.1089/big.2020.0263.
  10. H. Gao, “Design of network data information security monitoring system based on big data technology,” Procedia Computer Science, vol. 228, pp. 348–355, 2023, doi: 10.1016/j.procs.2023.11.040.
  11. D. Olszewski, “A data-scattering-preserving adaptive self-organizing map,” Engineering Applications of Artificial Intelligence, vol. 105, Art. no. 104420, 2021, doi: 10.1016/j.engappai.2021.104420.
  12. H. Yang, X. Li, W. Qiang, Y. Zhao, W. Zhang, and C. Tang, “A network traffic forecasting method based on SA optimized ARIMA–BP neural network,” Computer Networks, vol. 193, Art. no. 108102, 2021, doi: 10.1016/j.comnet.2021.108102.
  13. X. Li, M. Xu, P. Vijayakumar, N. Kumar, and X. Liu, “Detection of low-frequency and multi-stage attacks in Industrial Internet of Things,” IEEE Trans. Veh. Technol., vol. 69, no. 8, pp. 8820–8831, 2020, doi: 10.1109/TVT.2020.2995133.
  14. P. Zhou, G. Zhou, D. Wu, and M. Fei, “Detecting multi-stage attacks using sequence-to-sequence model,” Comput. Secur., vol. 105, Art. no. 102203, 2021, doi: 10.1016/j.cose.2021.102203.
  15. P. B. Weerakody, K. W. Wong, G. Wang, and W. Ela, “A review of irregular time series data handling with gated recurrent neural networks,” Neurocomputing, vol. 441, pp. 161–178, 2021, doi: 10.1016/j.neucom.2021.02.046.
  16. N. Basil, N. Cherif, M. B. Alhamadani, H. Hasan, and T. F. Agajie, “Comparative analysis of LSTM, HHOSOA, COAESPSO, and XGBoost models for time-series load forecasting,” Int. J. Comput. Eng. Artif. Intell., vol. 1, no. 1, Jun. 2026. Accessed: Sep. 13, 2026. https://ijceai.org/index.php/ijceai/article/view/13.
  17. M. A. Khan, “HCRNNIDS: Hybrid convolutional recurrent neural network-based network intrusion detection system,” Processes, vol. 9, no. 5, Art. no. 834, 2021, doi: 10.3390/pr9050834.
  18. M. Nakıp and E. Gelenbe, “Online self-supervised deep learning for intrusion detection systems,” IEEE Trans. Inf. Forensics Security, vol. 19, pp. 5668–5683, 2024, doi: 10.1109/TIFS.2024.3402148.
  19. M. A. Ferrag, O. Friha, D. Hamouda, L. Maglaras, and H. Janicke, “Edge-IIoTset: A new comprehensive realistic cyber security dataset of IoT and IIoT applications,” IEEE Access, vol. 10, pp. 40281–40306, 2022, doi: 10.1109/ACCESS.2022.3165809.
  20. D. Palko et al., “Cyber security risk modeling in distributed information systems,” Appl. Sci., vol. 13, no. 4, Art. no. 2393, 2023, doi: 10.3390/app13042393.
  21. E. Gelenbe and M. Nasereddin, "Adaptive Attack Mitigation for IoV Flood Attacks," in IEEE Internet of Things Journal, vol. 12, no. 5, pp. 4701-4714, 1 March1, 2025, doi: 10.1109/JIOT.2025.3529615.
  22. R. F. Abbas and S. H. Mohammed, “Packet tracer-based configuration and functional simulation of a campus VoIP communication system using Cisco Call Manager Express,” International Journal of Smart Control and Electrical Engineering Systems, vol. 1, no. 1, 2026. https://www.ijscees.org/index.php/pub/article/view/7.
  23. D. Palko et al., “Cyber security risk modeling in distributed information systems,” Applied Sciences, vol. 13, no. 4, Art. no. 2393, 2023, doi: 10.3390/app13042393.
  24. X. Li, M. Xu, P. Vijayakumar, N. Kumar, and X. Liu, “Detection of low-frequency and multi-stage attacks in industrial Internet of Things,” IEEE Transactions on Vehicular Technology, vol. 69, no. 8, pp. 8820–8831, 2020, doi: 10.1109/TVT.2020.2995133.
  25. G. A. Pavliotis, Stochastic Processes and Applications: Diffusion Processes, the Fokker–Planck and Langevin Equations. New York, NY, USA: Springer, 2014, doi:10.1007/978-1-4939-1323-7.
  26. M. Bampatsikos, I. Politis, T. Ioannidis and C. Xenakis, "Trust Score Prediction and Management in IoT Ecosystems Using Markov Chains and MADM Techniques," in IEEE Transactions on Consumer Electronics, vol. 71, no. 1, pp. 862-882, Feb. 2025, doi: 10.1109/TCE.2025.3531045.
  27. P. Zhou, G. Zhou, D. Wu, and M. Fei, “Detecting multi-stage attacks using sequence-to-sequence model,” Computers & Security, vol. 105, Art. no. 102203, 2021, doi: 10.1016/j.cose.2021.102203.