English
Related papers

Related papers: Data-Driven Threat Hunting Using Sysmon

200 papers

The ability to analyze network threats is very important in security research. Traditional approaches, involving sandboxing technology are limited to simulating a single host, missing local network attacks. This issue is addressed by…

Cryptography and Security · Computer Science 2020-07-17 Francisc Moldovan , Ciprian Oprisa

Cyber attacks are rapidly increasing with the advancement of technology and there is no protection for our information. To prevent future cyberattacks it is critical to promptly recognize cyberattacks and establish strong defense mechanisms…

Cryptography and Security · Computer Science 2025-09-16 Sawera Shahid , Umara Noor , Zahid Rashid

Signature-based Intrusion Detection Systems (IDS) detect malicious activities by matching network or host activity against predefined rules. These rules are derived from extensive Cyber Threat Intelligence (CTI), which includes attack…

Cryptography and Security · Computer Science 2025-08-27 Shaswata Mitra , Azim Bazarov , Martin Duclos , Sudip Mittal , Aritran Piplai , Md Rayhanur Rahman , Edward Zieglar , Shahram Rahimi

Intrusion detection systems (IDS) reinforce cyber defense by autonomously monitoring various data sources for traces of attacks. However, IDSs are also infamous for frequently raising false positives and alerts that are difficult to…

Cryptography and Security · Computer Science 2024-09-04 Max Landauer , Florian Skopik , Markus Wurzenberger

As antivirus and network intrusion detection systems have increasingly proven insufficient to detect advanced threats, large security operations centers have moved to deploy endpoint-based sensors that provide deeper visibility into…

Cryptography and Security · Computer Science 2015-08-26 Konstantin Berlin , David Slater , Joshua Saxe

SIEM systems are prevalent and play a critical role in a variety of analyst workflows in Security Operation Centers. However, modern SIEMs face a big challenge: they still cannot relieve analysts from the repetitive tasks involved in…

Cryptography and Security · Computer Science 2024-07-19 PeiYu Tseng , ZihDwo Yeh , Xushu Dai , Peng Liu

The escalating frequency and sophistication of cyber threats increased the need for their comprehensive understanding. This paper explores the intersection of geopolitical dynamics, cyber threat intelligence analysis, and advanced detection…

Cryptography and Security · Computer Science 2025-09-29 Gustavo Sánchez , Ghada Elbez , Veit Hagenmeyer

The ever-evolving capabilities of cyber attackers force security administrators to focus on the early identification of emerging threats. Targeted cyber attacks usually consist of several phases, from initial reconnaissance of the network…

Cryptography and Security · Computer Science 2022-06-22 Lukáš Sadlek , Pavel Čeleda , Daniel Tovarňák

Cyber attacks are growing in frequency and severity. Over the past year alone we have witnessed massive data breaches that stole personal information of millions of people and wide-scale ransomware attacks that paralyzed critical…

Social and Information Networks · Computer Science 2018-06-13 Palash Goyal , KSM Tozammel Hossain , Ashok Deb , Nazgol Tavabi , Nathan Bartley , Andr'es Abeliuk , Emilio Ferrara , Kristina Lerman

Log data are essential for intrusion detection and forensic investigations. However, manual log analysis is tedious due to high data volumes, heterogeneous event formats, and unstructured messages. Even though many automated methods for log…

Cryptography and Security · Computer Science 2026-03-05 Max Landauer , Wolfgang Hotwagner , Thorina Boenke , Florian Skopik , Markus Wurzenberger

For a long time threat modeling was treated as a manual, complicated process. However modern agile development methodologies and cloud computing technologies require adding automatic threat modeling approaches. This work considers two…

Cryptography and Security · Computer Science 2023-03-21 Andrei Brazhuk

Sophisticated cyber attacks present significant challenges for organizations in detecting and preventing such threats. To address this critical need for advanced defense mechanisms, we propose an Ensemble Defense System (EDS). An EDS is a…

Cryptography and Security · Computer Science 2024-01-09 Sarah Alharbi , Arshiya Khan

Attackers have developed ever more sophisticated and intelligent ways to hack information and communication technology systems. The extent of damage an individual hacker can carry out upon infiltrating a system is well understood. A…

Cryptography and Security · Computer Science 2018-08-20 Cosimo Ieracitano , Ahsan Adeel , Mandar Gogate , Kia Dashtipour , Francesco Carlo Morabito , Hadi Larijani , Ali Raza , Amir Hussain

In the dynamic cyber threat landscape, effective decision-making under uncertainty is crucial for maintaining robust information security. This paper introduces the Cyber Resilience Index (CRI), a threat-informed probabilistic approach to…

Cryptography and Security · Computer Science 2024-09-09 Lampis Alevizos , Vinh-Thong Ta

Multi-source logs provide a comprehensive overview of ongoing system activities, allowing for in-depth analysis to detect potential threats. A practical approach for threat detection involves explicit extraction of entity triples (subject,…

Software Engineering · Computer Science 2024-11-26 Zhuoran Tan , Christos Anagnostopoulos , Shameem P. Parambath , Jeremy Singer

Demand-Side Management (DSM) is a vital tool that can be used to ensure power system reliability and stability. In future smart grids, certain portions of a customers load usage could be under automatic control with a cyber-enabled DSM…

Signal Processing · Electrical Eng. & Systems 2019-10-01 Kostas Hatalis , Parv Venkitasubramaniam , Shalinee Kishore

Traditional threat modeling occurs during design, but cloud deployments introduce unanticipated threats, especially multi-stage attacks chaining vulnerabilities across trust boundaries. Existing security tools analyze components in…

Cryptography and Security · Computer Science 2026-03-25 Nicholas Pecka , Lotfi Ben Othmane , Bharat Bhargava , Renee Bryce

In the digital era, threat actors employ sophisticated techniques for which, often, digital traces in the form of textual data are available. Cyber Threat Intelligence~(CTI) is related to all the solutions inherent to data collection,…

Cryptography and Security · Computer Science 2023-11-16 Marco Arazzi , Dincy R. Arikkat , Serena Nicolazzo , Antonino Nocera , Rafidha Rehiman K. A. , Vinod P. , Mauro Conti

To assure cyber security of an enterprise, typically SIEM (Security Information and Event Management) system is in place to normalize security event from different preventive technologies and flag alerts. Analysts in the security operation…

Cryptography and Security · Computer Science 2018-01-03 Wangyan Feng , Shuning Wu , Xiaodan Li , Kevin Kunkle

In recent years, the landscape of software threats has become significantly more dynamic and distributed. Security vulnerabilities are no longer discovered and shared only through formal channels such as public vulnerability databases or…

Software Engineering · Computer Science 2025-10-07 Chengwei Liu , Wenbo Guo , Yuxin Zhang , Limin Wang , Sen Chen , Lei Bu , Yang Liu