2019 IEEE European Symposium on Security and Privacy (EuroS&P) 2019
DOI: 10.1109/eurosp.2019.00033
|View full text |Cite
|
Sign up to set email alerts
|

Discovering Correlations: A Formal Definition of Causal Dependency Among Heterogeneous Events

Abstract: In order to supervise the security of a large infrastructure, the administrator deploys multiple sensors and intrusion detection systems on several critical places in the system. It is easier to explain and detect attacks if more events are logged. Starting from a suspicious event (appearing as a log entry), the administrator can start his investigation by manually building the set of previous events that are linked to this event of interest. Accordingly, the administrator attempts to identify links among the … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2020
2020
2024
2024

Publication Types

Select...
3
1
1

Relationship

1
4

Authors

Journals

citations
Cited by 5 publications
(1 citation statement)
references
References 30 publications
0
1
0
Order By: Relevance
“…These proposals are however limited since they only consider one type of event format. This contrasts with [32] in which the authors propose to discover causal dependency in heterogeneous events to detect multi-steps attacks. Hercule [24] models network log entries also coming from multiple sources of data as nodes in a graph.…”
Section: Using Graph For Analyzing Security Eventsmentioning
confidence: 96%
“…These proposals are however limited since they only consider one type of event format. This contrasts with [32] in which the authors propose to discover causal dependency in heterogeneous events to detect multi-steps attacks. Hercule [24] models network log entries also coming from multiple sources of data as nodes in a graph.…”
Section: Using Graph For Analyzing Security Eventsmentioning
confidence: 96%