The platform will undergo maintenance on Sep 14 at about 7:45 AM EST and will be unavailable for approximately 2 hours.
2016
DOI: 10.1002/sec.1756
|View full text |Cite
|
Sign up to set email alerts
|

Causal knowledge analysis for detecting and modeling multi‐step attacks

Abstract: In order to understand the security level of an organization network, detection methods are important to tackle the probable risks of the attackers' malicious activities. Intrusion detection systems, as detection solutions of the defense in depth concept, are one of the main devices to record and analyze suspicious behaviors. Besides the benefits of these systems for security enhancement, they will bring some challenges and issues for security administrators. A large number of raw alerts generated by the intru… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2018
2018
2023
2023

Publication Types

Select...
4
1
1

Relationship

0
6

Authors

Journals

citations
Cited by 15 publications
(1 citation statement)
references
References 27 publications
0
1
0
Order By: Relevance
“…Cluster Correlation Analysis e clustering alert correlation method associates alert information with some identical or similar features, that is, clustering by the similarity between alert a ribute values, such as the same destination address, the same a ack source, a ack means, etc. Ahmadianramaki et al [1] proposed a three-layer processing framework that uses causal knowledge to correlate alerts, automatically extracts causal relationships between alerts, builds the a ack scenario using Bayesian networks. And further predict the most likely next a ack behavior.…”
Section: Related Workmentioning
confidence: 99%
“…Cluster Correlation Analysis e clustering alert correlation method associates alert information with some identical or similar features, that is, clustering by the similarity between alert a ribute values, such as the same destination address, the same a ack source, a ack means, etc. Ahmadianramaki et al [1] proposed a three-layer processing framework that uses causal knowledge to correlate alerts, automatically extracts causal relationships between alerts, builds the a ack scenario using Bayesian networks. And further predict the most likely next a ack behavior.…”
Section: Related Workmentioning
confidence: 99%