Matches in SemOpenAlex for { <https://semopenalex.org/work/W203201158> ?p ?o ?g. }
- W203201158 abstract "Rapidly evolving IT infrastructures bring beneficial effects to society and promote information sharing and use. However, vulnerabilities create opportunities for hostile users to perform malicious activities and IT security has gradually turned into a critical research area for organizations and governments. Processes of decision making in large organizations are widely influenced by their capability of detecting malicious activities effectively, and by the correctness in analyzing suspicious phenomena, which can be observed by a number of security sensors deployed in such large networks. Several techniques are currently employed to detect incidents starting from captured security-related events within networks and computer systems. However, the large volume of observable events, the continuous sophistication and changes in attack strategies make it challenging to provide effective solutions to detect and reconstruct cyber-security incidents. In particular, advanced multi-stage attacks tend to remain undiscovered because common security mechanisms can generally detect and flag harmful activity – sometimes with unsatisfactory false alert rates – but they are not able to draw a big picture of the incidents. Since such task is usually performed by security experts in full, it may be expensive and prone to errors. Therefore, it is essential to develop procedures for combining large heterogeneous datasets and system’s information in meaningful way, and for supplying detailed information to IT security management. By examining realistic multi-stage incidents, this thesis proposes the design of a model to correlate detectable suspicious events by combining complementary state of the art methods, which perform correlation along different axis. Thus, it aims at providing standard data formats, prioritizing and clustering data, increasing confidence about threats, finding relations of causality between suspicious events and eventually reconstructing multi-stage incidents. In addition, reviewing the most influential scientific papers gives us the chance to categorize the techniques and suggest practices for further implementation." @default.
- W203201158 created "2016-06-24" @default.
- W203201158 creator A5049494590 @default.
- W203201158 date "2013-07-12" @default.
- W203201158 modified "2023-09-23" @default.
- W203201158 title "Event correlation for detecting advanced multi-stage cyber-attacks" @default.
- W203201158 cites W109441098 @default.
- W203201158 cites W124349154 @default.
- W203201158 cites W1546161684 @default.
- W203201158 cites W1546690352 @default.
- W203201158 cites W1549716092 @default.
- W203201158 cites W1554596310 @default.
- W203201158 cites W1562402498 @default.
- W203201158 cites W1587979610 @default.
- W203201158 cites W1621186777 @default.
- W203201158 cites W1670263352 @default.
- W203201158 cites W1684452600 @default.
- W203201158 cites W191098608 @default.
- W203201158 cites W1968492600 @default.
- W203201158 cites W1974102697 @default.
- W203201158 cites W1999448603 @default.
- W203201158 cites W2006862475 @default.
- W203201158 cites W2011078788 @default.
- W203201158 cites W2019207321 @default.
- W203201158 cites W2036512235 @default.
- W203201158 cites W2048125321 @default.
- W203201158 cites W2057855325 @default.
- W203201158 cites W2072113943 @default.
- W203201158 cites W2073165180 @default.
- W203201158 cites W2103806672 @default.
- W203201158 cites W2108118522 @default.
- W203201158 cites W2115149820 @default.
- W203201158 cites W2128116119 @default.
- W203201158 cites W2130087897 @default.
- W203201158 cites W2136451344 @default.
- W203201158 cites W2137928260 @default.
- W203201158 cites W2141200504 @default.
- W203201158 cites W2143692712 @default.
- W203201158 cites W2152449272 @default.
- W203201158 cites W2159126236 @default.
- W203201158 cites W2161830378 @default.
- W203201158 cites W2170701348 @default.
- W203201158 cites W2171635164 @default.
- W203201158 cites W2542498933 @default.
- W203201158 cites W2678934292 @default.
- W203201158 cites W2797148637 @default.
- W203201158 cites W2912625373 @default.
- W203201158 cites W3193347044 @default.
- W203201158 cites W3214823556 @default.
- W203201158 cites W351141490 @default.
- W203201158 hasPublicationYear "2013" @default.
- W203201158 type Work @default.
- W203201158 sameAs 203201158 @default.
- W203201158 citedByCount "0" @default.
- W203201158 crossrefType "journal-article" @default.
- W203201158 hasAuthorship W203201158A5049494590 @default.
- W203201158 hasConcept C121332964 @default.
- W203201158 hasConcept C127413603 @default.
- W203201158 hasConcept C144024400 @default.
- W203201158 hasConcept C165696696 @default.
- W203201158 hasConcept C168725872 @default.
- W203201158 hasConcept C199360897 @default.
- W203201158 hasConcept C201307755 @default.
- W203201158 hasConcept C201995342 @default.
- W203201158 hasConcept C2779662365 @default.
- W203201158 hasConcept C2780451532 @default.
- W203201158 hasConcept C36289849 @default.
- W203201158 hasConcept C38652104 @default.
- W203201158 hasConcept C41008148 @default.
- W203201158 hasConcept C55439883 @default.
- W203201158 hasConcept C62520636 @default.
- W203201158 hasConceptScore W203201158C121332964 @default.
- W203201158 hasConceptScore W203201158C127413603 @default.
- W203201158 hasConceptScore W203201158C144024400 @default.
- W203201158 hasConceptScore W203201158C165696696 @default.
- W203201158 hasConceptScore W203201158C168725872 @default.
- W203201158 hasConceptScore W203201158C199360897 @default.
- W203201158 hasConceptScore W203201158C201307755 @default.
- W203201158 hasConceptScore W203201158C201995342 @default.
- W203201158 hasConceptScore W203201158C2779662365 @default.
- W203201158 hasConceptScore W203201158C2780451532 @default.
- W203201158 hasConceptScore W203201158C36289849 @default.
- W203201158 hasConceptScore W203201158C38652104 @default.
- W203201158 hasConceptScore W203201158C41008148 @default.
- W203201158 hasConceptScore W203201158C55439883 @default.
- W203201158 hasConceptScore W203201158C62520636 @default.
- W203201158 hasLocation W2032011581 @default.
- W203201158 hasOpenAccess W203201158 @default.
- W203201158 hasPrimaryLocation W2032011581 @default.
- W203201158 hasRelatedWork W1992226504 @default.
- W203201158 hasRelatedWork W2239878508 @default.
- W203201158 hasRelatedWork W2242585608 @default.
- W203201158 hasRelatedWork W2743411104 @default.
- W203201158 hasRelatedWork W2768401148 @default.
- W203201158 hasRelatedWork W2802296803 @default.
- W203201158 hasRelatedWork W2886282970 @default.
- W203201158 hasRelatedWork W2891055653 @default.
- W203201158 hasRelatedWork W2913886887 @default.
- W203201158 hasRelatedWork W2938555005 @default.
- W203201158 hasRelatedWork W2970073850 @default.