Matches in SemOpenAlex for { <https://semopenalex.org/work/W4387394709> ?p ?o ?g. }
- W4387394709 endingPage "103761" @default.
- W4387394709 startingPage "103761" @default.
- W4387394709 abstract "Host-based Intrusion Detection System (HIDS) is an effective last line of defense for defending against cyber security attacks after perimeter defenses (e.g., Network-based Intrusion Detection System and Firewall) have failed or been bypassed. HIDS is widely adopted in the industry as HIDS is ranked among the top two most used security tools by Security Operation Centers (SOC) of organizations. Although effective and efficient HIDS is highly desirable for industrial organizations, the evolution of increasingly complex attack patterns causes several challenges resulting in performance degradation of HIDS (e.g., high false alert rate creating alert fatigue for SOC staff). Since Natural Language Processing (NLP) methods are better suited for identifying complex attack patterns, an increasing number of HIDS are leveraging the advances in NLP that have shown effective and efficient performance in precisely detecting low footprint, zero-day attacks and predicting an attacker’s next steps. This active research trend of using NLP in HIDS demands a synthesized and comprehensive body of knowledge of NLP-based HIDS. Despite the drastically growing adoption of NLP in HIDS development, there has been relatively little effort allocated to systematically analyze and synthesize the available peer review literature to understand how NLP is used in HIDS development. The lack of a synthesized and comprehensive body of knowledge on such an important topic motivated us to conduct a Systematic Literature Review (SLR) of the papers on the end-to-end pipeline of the use of NLP in HIDS development. For the end-to-end NLP-based HIDS development pipeline, we identify, taxonomically categorize and systematically compare the state-of-the-art of NLP methods usage in HIDS, attacks detected by these NLP methods, datasets and evaluation metrics which are used to evaluate the NLP-based HIDS. We highlight the relevant prevalent practices, considerations, advantages and limitations to support the HIDS developers. We also outline the future research directions for the NLP-based HIDS development." @default.
- W4387394709 created "2023-10-07" @default.
- W4387394709 creator A5003339331 @default.
- W4387394709 creator A5058693284 @default.
- W4387394709 creator A5086202577 @default.
- W4387394709 date "2023-11-01" @default.
- W4387394709 modified "2023-10-13" @default.
- W4387394709 title "NLP methods in host-based intrusion detection systems: A systematic review and future directions" @default.
- W4387394709 cites W1489073918 @default.
- W4387394709 cites W1975675278 @default.
- W4387394709 cites W1979290264 @default.
- W4387394709 cites W1984350393 @default.
- W4387394709 cites W2075457132 @default.
- W4387394709 cites W2112841646 @default.
- W4387394709 cites W2118372007 @default.
- W4387394709 cites W2124808847 @default.
- W4387394709 cites W2128792405 @default.
- W4387394709 cites W2137365926 @default.
- W4387394709 cites W2139836766 @default.
- W4387394709 cites W2145338466 @default.
- W4387394709 cites W2167240430 @default.
- W4387394709 cites W2250539671 @default.
- W4387394709 cites W2342408547 @default.
- W4387394709 cites W2467405173 @default.
- W4387394709 cites W2468321486 @default.
- W4387394709 cites W2493916176 @default.
- W4387394709 cites W2529087958 @default.
- W4387394709 cites W2559588458 @default.
- W4387394709 cites W2588787044 @default.
- W4387394709 cites W2590373591 @default.
- W4387394709 cites W2601474892 @default.
- W4387394709 cites W2603119212 @default.
- W4387394709 cites W2735864825 @default.
- W4387394709 cites W2738336658 @default.
- W4387394709 cites W2801626544 @default.
- W4387394709 cites W2803881474 @default.
- W4387394709 cites W2885999345 @default.
- W4387394709 cites W2893123663 @default.
- W4387394709 cites W2896373185 @default.
- W4387394709 cites W2900713154 @default.
- W4387394709 cites W2910705748 @default.
- W4387394709 cites W2919021187 @default.
- W4387394709 cites W2924689635 @default.
- W4387394709 cites W2926701059 @default.
- W4387394709 cites W2929803724 @default.
- W4387394709 cites W2952767732 @default.
- W4387394709 cites W2958285686 @default.
- W4387394709 cites W2980576170 @default.
- W4387394709 cites W2980759501 @default.
- W4387394709 cites W2981025625 @default.
- W4387394709 cites W2986055611 @default.
- W4387394709 cites W2988790801 @default.
- W4387394709 cites W3014407644 @default.
- W4387394709 cites W3017093935 @default.
- W4387394709 cites W3021208824 @default.
- W4387394709 cites W3033777149 @default.
- W4387394709 cites W3035680449 @default.
- W4387394709 cites W3046830338 @default.
- W4387394709 cites W3047132966 @default.
- W4387394709 cites W3121707215 @default.
- W4387394709 cites W3123908207 @default.
- W4387394709 cites W3159364646 @default.
- W4387394709 cites W3160220648 @default.
- W4387394709 cites W3163963286 @default.
- W4387394709 cites W3171239643 @default.
- W4387394709 cites W3185296261 @default.
- W4387394709 cites W433644524 @default.
- W4387394709 doi "https://doi.org/10.1016/j.jnca.2023.103761" @default.
- W4387394709 hasPublicationYear "2023" @default.
- W4387394709 type Work @default.
- W4387394709 citedByCount "0" @default.
- W4387394709 crossrefType "journal-article" @default.
- W4387394709 hasAuthorship W4387394709A5003339331 @default.
- W4387394709 hasAuthorship W4387394709A5058693284 @default.
- W4387394709 hasAuthorship W4387394709A5086202577 @default.
- W4387394709 hasBestOaLocation W43873947091 @default.
- W4387394709 hasConcept C115304011 @default.
- W4387394709 hasConcept C119857082 @default.
- W4387394709 hasConcept C121332964 @default.
- W4387394709 hasConcept C124017977 @default.
- W4387394709 hasConcept C126831891 @default.
- W4387394709 hasConcept C154945302 @default.
- W4387394709 hasConcept C183915046 @default.
- W4387394709 hasConcept C18903297 @default.
- W4387394709 hasConcept C199360897 @default.
- W4387394709 hasConcept C35525427 @default.
- W4387394709 hasConcept C38652104 @default.
- W4387394709 hasConcept C41008148 @default.
- W4387394709 hasConcept C43521106 @default.
- W4387394709 hasConcept C74650414 @default.
- W4387394709 hasConcept C77714075 @default.
- W4387394709 hasConcept C86803240 @default.
- W4387394709 hasConceptScore W4387394709C115304011 @default.
- W4387394709 hasConceptScore W4387394709C119857082 @default.
- W4387394709 hasConceptScore W4387394709C121332964 @default.
- W4387394709 hasConceptScore W4387394709C124017977 @default.
- W4387394709 hasConceptScore W4387394709C126831891 @default.
- W4387394709 hasConceptScore W4387394709C154945302 @default.