Matches in SemOpenAlex for { <https://semopenalex.org/work/W2963490295> ?p ?o ?g. }
- W2963490295 abstract "Cyber-attacks become more sophisticated and complex especially when adversaries steal user credentials to traverse the network of an organization. Detecting a breach is extremely difficult and this is confirmed by the findings of studies related to cyber-attacks on organizations. A study conducted last year by IBM found that it takes 206 days on average to US companies to detect a data breach. As a consequence, the effectiveness of existing defensive tools is in question. In this work we deal with the detection of malicious authentication events, which are responsible for effective execution of the stealthy attack, called lateral movement. Authentication event logs produce a pure categorical feature space which creates methodological challenges for developing outlier detection algorithms. We propose an auto semi-supervised outlier ensemble detector that does not leverage the ground truth to learn the normal behavior. The automatic nature of our methodology is supported by established unsupervised outlier ensemble theory. We test the performance of our detector on a real-world cyber security dataset provided publicly by the Los Alamos National Lab. Overall, our experiments show that our proposed detector outperforms existing algorithms and produces a 0 False Negative Rate without missing any malicious login event and a False Positive Rate which improves the state-of-the-art. In addition, by detecting malicious authentication events, compared to the majority of the existing works which focus solely on detecting malicious users or computers, we are able to provide insights regarding when and at which systems malicious login events happened. Beyond the application on a public dataset we are working with our industry partner, POST Luxembourg, to employ the proposed detector on their network." @default.
- W2963490295 created "2019-07-30" @default.
- W2963490295 creator A5004384801 @default.
- W2963490295 creator A5022525974 @default.
- W2963490295 creator A5069228908 @default.
- W2963490295 creator A5082230185 @default.
- W2963490295 date "2020-01-01" @default.
- W2963490295 modified "2023-09-27" @default.
- W2963490295 title "Auto Semi-supervised Outlier Detection for Malicious Authentication Events" @default.
- W2963490295 cites W164607750 @default.
- W2963490295 cites W1970978220 @default.
- W2963490295 cites W1975188201 @default.
- W2963490295 cites W2056081083 @default.
- W2963490295 cites W2086342284 @default.
- W2963490295 cites W2101549186 @default.
- W2963490295 cites W2131989759 @default.
- W2963490295 cites W2132870739 @default.
- W2963490295 cites W2142047467 @default.
- W2963490295 cites W2144182447 @default.
- W2963490295 cites W2148583977 @default.
- W2963490295 cites W2170902455 @default.
- W2963490295 cites W2285831592 @default.
- W2963490295 cites W2288636546 @default.
- W2963490295 cites W2293496281 @default.
- W2963490295 cites W2296719434 @default.
- W2963490295 cites W2302058010 @default.
- W2963490295 cites W2305365322 @default.
- W2963490295 cites W2337344967 @default.
- W2963490295 cites W2476891002 @default.
- W2963490295 cites W2518732252 @default.
- W2963490295 cites W2554388950 @default.
- W2963490295 cites W2554451579 @default.
- W2963490295 cites W2556800116 @default.
- W2963490295 cites W2561521190 @default.
- W2963490295 cites W2562370852 @default.
- W2963490295 cites W2750880678 @default.
- W2963490295 cites W2756364779 @default.
- W2963490295 cites W2766503369 @default.
- W2963490295 cites W2804964061 @default.
- W2963490295 cites W2902415114 @default.
- W2963490295 cites W2963224980 @default.
- W2963490295 cites W4235091326 @default.
- W2963490295 cites W42722137 @default.
- W2963490295 doi "https://doi.org/10.1007/978-3-030-43887-6_14" @default.
- W2963490295 hasPublicationYear "2020" @default.
- W2963490295 type Work @default.
- W2963490295 sameAs 2963490295 @default.
- W2963490295 citedByCount "1" @default.
- W2963490295 countsByYear W29634902952021 @default.
- W2963490295 crossrefType "book-chapter" @default.
- W2963490295 hasAuthorship W2963490295A5004384801 @default.
- W2963490295 hasAuthorship W2963490295A5022525974 @default.
- W2963490295 hasAuthorship W2963490295A5069228908 @default.
- W2963490295 hasAuthorship W2963490295A5082230185 @default.
- W2963490295 hasConcept C113324615 @default.
- W2963490295 hasConcept C119857082 @default.
- W2963490295 hasConcept C121332964 @default.
- W2963490295 hasConcept C124101348 @default.
- W2963490295 hasConcept C148417208 @default.
- W2963490295 hasConcept C153083717 @default.
- W2963490295 hasConcept C154945302 @default.
- W2963490295 hasConcept C2779662365 @default.
- W2963490295 hasConcept C38652104 @default.
- W2963490295 hasConcept C41008148 @default.
- W2963490295 hasConcept C5274069 @default.
- W2963490295 hasConcept C62520636 @default.
- W2963490295 hasConcept C64869954 @default.
- W2963490295 hasConcept C739882 @default.
- W2963490295 hasConcept C76155785 @default.
- W2963490295 hasConcept C94915269 @default.
- W2963490295 hasConceptScore W2963490295C113324615 @default.
- W2963490295 hasConceptScore W2963490295C119857082 @default.
- W2963490295 hasConceptScore W2963490295C121332964 @default.
- W2963490295 hasConceptScore W2963490295C124101348 @default.
- W2963490295 hasConceptScore W2963490295C148417208 @default.
- W2963490295 hasConceptScore W2963490295C153083717 @default.
- W2963490295 hasConceptScore W2963490295C154945302 @default.
- W2963490295 hasConceptScore W2963490295C2779662365 @default.
- W2963490295 hasConceptScore W2963490295C38652104 @default.
- W2963490295 hasConceptScore W2963490295C41008148 @default.
- W2963490295 hasConceptScore W2963490295C5274069 @default.
- W2963490295 hasConceptScore W2963490295C62520636 @default.
- W2963490295 hasConceptScore W2963490295C64869954 @default.
- W2963490295 hasConceptScore W2963490295C739882 @default.
- W2963490295 hasConceptScore W2963490295C76155785 @default.
- W2963490295 hasConceptScore W2963490295C94915269 @default.
- W2963490295 hasLocation W29634902951 @default.
- W2963490295 hasOpenAccess W2963490295 @default.
- W2963490295 hasPrimaryLocation W29634902951 @default.
- W2963490295 hasRelatedWork W2466222482 @default.
- W2963490295 hasRelatedWork W2766684344 @default.
- W2963490295 hasRelatedWork W2784028125 @default.
- W2963490295 hasRelatedWork W2785509559 @default.
- W2963490295 hasRelatedWork W2789389144 @default.
- W2963490295 hasRelatedWork W2804964061 @default.
- W2963490295 hasRelatedWork W2907421153 @default.
- W2963490295 hasRelatedWork W2963125256 @default.
- W2963490295 hasRelatedWork W3025076718 @default.
- W2963490295 hasRelatedWork W3094043420 @default.
- W2963490295 hasRelatedWork W3120790981 @default.