English
Related papers

Related papers: Multi-Stage Attack Detection via Kill Chain State …

200 papers

In this paper, we present a study that proposes a three-stage classifier model which employs a machine learning algorithm to develop an intrusion detection and identification system for tens of different types of attacks against industrial…

Cryptography and Security · Computer Science 2020-12-18 Ahsan Al Zaki Khan , Gursel Serpen

Modern industrial systems face a growing threat from sophisticated cyberattacks that can cause significant operational disruptions. This work presents a novel methodology for identification of the most critical cyberattacks that may disrupt…

Systems and Control · Electrical Eng. & Systems 2024-05-31 Bruno Paes Leao , Jagannadh Vempati , Siddharth Bhela , Tobias Ahlgrim , Daniel Arnold

Alert correlation is a system which receives alerts from heterogeneous Intrusion Detection Systems and reduces false alerts, detects high level patterns of attacks, increases the meaning of occurred incidents, predicts the future states of…

Cryptography and Security · Computer Science 2018-11-05 Seyed Ali Mirheidari , Sajjad Arshad , Rasool Jalili

Modern smart grid systems are heavily dependent on Information and Communication Technology, and this dependency makes them prone to cyberattacks. The occurrence of a cyberattack has increased in recent years resulting in substantial damage…

Cryptography and Security · Computer Science 2021-08-03 Yasir Ali Farrukh , Irfan Khan , Zeeshan Ahmad , Rajvikram Madurai Elavarasan

We study the problem of detecting an attack on a stochastic cyber-physical system. We aim to treat the problem in its most general form. We start by introducing the notion of asymptotically detectable attacks, as those attacks introducing…

Systems and Control · Electrical Eng. & Systems 2021-03-05 Damián Marelli , Tianju Sui , Minyue Fu , Renquan Lu

Protecting the security of the train control system is a critical issue to ensure the safe and reliable operation of high-speed trains. Scientific modeling and analysis for the security risk is a promising way to guarantee system security.…

Systems and Control · Electrical Eng. & Systems 2025-10-01 Zikai Zhang

Advanced Persistent Threats (APTs) are difficult to detect due to their "low-and-slow" attack patterns and frequent use of zero-day exploits. We present UNICORN, an anomaly-based APT detector that effectively leverages data provenance…

Cryptography and Security · Computer Science 2020-01-15 Xueyuan Han , Thomas Pasquier , Adam Bates , James Mickens , Margo Seltzer

We evaluate the autonomous cyber-attack capabilities of frontier AI models on two purpose-built cyber ranges-a 32-step corporate network attack and a 7-step industrial control system attack-that require chaining heterogeneous capabilities…

Banking Trojans, botnets are primary drivers of financially-motivated cybercrime. In this paper, we first analyzed how an APT-based banking botnet works step by step through the whole lifecycle. Specifically, we present a multi-stage system…

Cryptography and Security · Computer Science 2019-07-26 Li Ling , Zhiqiang Gao , Michael A Silas , Ian Lee , Erwan A Le Doeuff

Connected vehicles (CVs), because of the external connectivity with other CVs and connected infrastructure, are vulnerable to cyberattacks that can instantly compromise the safety of the vehicle itself and other connected vehicles and…

Cryptography and Security · Computer Science 2021-08-04 Sakib Mahmud Khan , Gurcan Comert , Mashrur Chowdhury

As the complexity of modern systems increases, so does the importance of assessing their security posture through effective vulnerability management and threat modeling techniques. One powerful tool in the arsenal of cybersecurity…

Cryptography and Security · Computer Science 2024-08-13 Renascence Tarafder Prapty , Ashish Kundu , Arun Iyengar

With the increase of connectivity in power grid, a cascading failure may be triggered by the failure of a transmission line, which can lead to substantial economic losses and serious negative social impacts. Therefore, it is very important…

Systems and Control · Electrical Eng. & Systems 2020-12-01 Liang Yu , Zhen Gao , Shuqi Qin , Meng Zhang , Chao Shen , Xiaohong Guan , Dong Yue

Attack Trees are a graphical model of security used to study threat scenarios. While visually appealing and supported by solid theories and effective tools, one of their main drawbacks remains the amount of effort required by security…

Cryptography and Security · Computer Science 2024-09-13 Alyzia-Maria Konsta , Gemma Di Federico , Alberto Lluch Lafuente , Andrea Burattin

Automated cyber defense (ACD) seeks to protect computer networks with minimal or no human intervention, reacting to intrusions by taking corrective actions such as isolating hosts, resetting services, deploying decoys, or updating access…

Machine Learning · Computer Science 2026-01-12 Yu Li , Sizhe Tang , Rongqian Chen , Fei Xu Yu , Guangyu Jiang , Mahdi Imani , Nathaniel D. Bastian , Tian Lan

Advanced Persistent Threat (APT) attribution is a critical challenge in cybersecurity and implies the process of accurately identifying the perpetrators behind sophisticated cyber attacks. It can significantly enhance defense mechanisms and…

Cryptography and Security · Computer Science 2024-10-08 Nanda Rani , Bikash Saha , Sandeep Kumar Shukla

Provenance-based Intrusion Detection Systems (PIDSes) have been widely used to detect Advanced Persistent Threats (APTs). Although many studies achieve high performance in the evaluations of their original papers, their performance in…

Cryptography and Security · Computer Science 2026-03-25 Yue Xiao , Ling Jiang , Sen Nie , Ding Li , Shi Wu , Ke Xu , Qi Li

The objectives of cyberattacks are becoming sophisticated, and attackers are concealing their identity by masquerading as other attackers. Cyber threat intelligence (CTI) is gaining attention as a way to collect meaningful knowledge to…

Cryptography and Security · Computer Science 2019-10-08 Daegeon Kim , Huy Kang Kim

Cybersecurity attacks are growing both in frequency and sophistication over the years. This increasing sophistication and complexity call for more advancement and continuous innovation in defensive strategies. Traditional methods of…

Machine Learning · Computer Science 2020-01-20 Antoine Delplace , Sheryl Hermoso , Kristofer Anandita

Despite rapid advances in image-based machine learning, the threat identification of a knife wielding attacker has not garnered substantial academic attention. This relative research gap appears less understandable given the high knife…

Computer Vision and Pattern Recognition · Computer Science 2020-04-09 David A. Noever , Sam E. Miller Noever

The goal of this note is to assess whether simple machine learning algorithms can be used to determine whether and how a given network has been attacked. The procedure is based on the $k$-Nearest Neighbor and the Random Forest…

Physics and Society · Physics 2023-08-30 Davide Coppes , Paolo Cermelli