中文
相关论文

相关论文: HOLMES: Real-time APT Detection through Correlatio…

200 篇论文

Cyber attacks are often identified using system and network logs. There have been significant prior works that utilize provenance graphs and ML techniques to detect attacks, specifically advanced persistent threats, which are very difficult…

密码学与安全 · 计算机科学 2023-11-13 Sihat Afnan , Mushtari Sadia , Shahrear Iqbal , Anindya Iqbal

Collaboration among multiple organizations is imperative for contemporary intrusion detection. As modern threats become well sophisticated it is difficult for organizations to defend with threat context local to their networks alone.…

密码学与安全 · 计算机科学 2016-02-09 Sashank Dara , V. N. Muralidhara

Network intrusion detection sensors are usually built around low level models of network traffic. This means that their output is of a similarly low level and as a consequence, is difficult to analyze. Intrusion alert correlation is the…

密码学与安全 · 计算机科学 2010-07-05 Gianni Tedesco , Uwe Aickelin

Sixth Generation (6G) wireless networks, which are expected to be deployed in the 2030s, have already created great excitement in academia and the private sector with their extremely high communication speed and low latency rates. However,…

密码学与安全 · 计算机科学 2025-10-14 Muhammed Golec , Yaser Khamayseh , Suhib Bani Melhem , Abdulmalik Alwarafy

Host-based intrusion detection system (HIDS) is a key defense component to protect the organizations from advanced threats like Advanced Persistent Threats (APT). By analyzing the fine-grained logs with approaches like data provenance, HIDS…

密码学与安全 · 计算机科学 2025-07-16 Danyu Sun , Jinghuai Zhang , Jiacen Xu , Yu Zheng , Yuan Tian , Zhou Li

Many real-world scenarios involving streaming information can be represented as temporal graphs, where data flows through dynamic changes in edges over time. Anomaly detection in this context has the objective of identifying unusual…

机器学习 · 计算机科学 2025-12-01 Simone Mungari , Albert Bifet , Giuseppe Manco , Bernhard Pfahringer

In light of the mounting imperative for public security, the necessity for automated threat detection in high-risk scenarios is becoming increasingly pressing. However, existing methods generally suffer from the problems of uninterpretable…

计算机视觉与模式识别 · 计算机科学 2025-07-29 Yuhan Wang , Cheng Liu , Daou Zhang , Zihan Zhao , Jinyang Chen , Purui Dong , Zuyuan Yu , Ziru Wang , Weichao Wu

Intrusion detection systems (IDS) reinforce cyber defense by autonomously monitoring various data sources for traces of attacks. However, IDSs are also infamous for frequently raising false positives and alerts that are difficult to…

密码学与安全 · 计算机科学 2024-09-04 Max Landauer , Florian Skopik , Markus Wurzenberger

The new cyber attack pattern of advanced persistent threat (APT) has posed a serious threat to modern society. This paper addresses the APT defense problem, i.e., the problem of how to effectively defend against an APT campaign. Based on a…

密码学与安全 · 计算机科学 2017-12-29 Pengdeng Li , Lu-Xing Yang , Xiaofan Yang , Qingyu Xiong , Junhao Wen , Yuan Yan Tang

The exponential growth of Internet traffic has made public servers increasingly vulnerable to unauthorized accesses and intrusions. In addition to maintaining low latency for the client, filtering unauthorized accesses has become one of the…

密码学与安全 · 计算机科学 2009-06-30 Ram Kumar Singh , Prof. T. Ramajujam

This paper presents PULSAR, a framework for pre-empting Advanced Persistent Threats (APTs). PULSAR employs a probabilistic graphical model (specifically a Factor Graph) to infer the time evolution of an attack based on observed security…

密码学与安全 · 计算机科学 2019-03-22 Phuong Cao

Advanced Persistent Threats (APTs) pose critical challenges to modern cybersecurity due to their multi-stage and stealthy nature. While provenance-based detection approaches show promise in capturing causal attack semantics, current threat…

密码学与安全 · 计算机科学 2026-03-11 Wenhao Yan , Ning An , Linxu Li , Bingsheng Bi , Bo Jiang , Zhigang Lu , Baoxu Liu , Junrong Liu , Cong Dong

The detection of BGP prefix hijacking attacks has been the focus of research for more than a decade. However, state-of-the-art techniques fall short of detecting more elaborate types of attack. To study such attacks, we devise a novel…

网络与互联网体系结构 · 计算机科学 2016-07-04 Johann Schlamp , Ralph Holz , Quentin Jacquemart , Georg Carle , Ernst W. Biersack

Cyberthreats are a permanent concern in our modern technological world. In the recent years, sophisticated traffic analysis techniques and anomaly detection (AD) algorithms have been employed to face the more and more subversive adversarial…

机器学习 · 计算机科学 2022-05-17 Paul Irofti , Andrei Pătraşcu , Andrei Iulian Hîji

Advanced Persistent Threats (APT) attacks have plagued modern enterprises, causing significant financial losses. To counter these attacks, researchers propose techniques that capture the complex and stealthy scenarios of APT attacks by…

密码学与安全 · 计算机科学 2023-11-07 Shaofei Li , Feng Dong , Xusheng Xiao , Haoyu Wang , Fei Shao , Jiedong Chen , Yao Guo , Xiangqun Chen , Ding Li

To defend against Advanced Persistent Threats on the endpoint, threat hunting employs security knowledge such as cyber threat intelligence to continuously analyze system audit logs through retrospective scanning, querying, or pattern…

密码学与安全 · 计算机科学 2025-08-11 Mingjun Ma , Tiantian Zhu , Shuang Li , Tieming Chen , Mingqi Lv , Zhengqiu Weng , Guolang Chen

Modern DDoS defense systems rely on probabilistic monitoring algorithms to identify flows that exceed a volume threshold and should thus be penalized. Commonly, classic sketch algorithms are considered sufficiently accurate for usage in…

密码学与安全 · 计算机科学 2023-07-10 Simon Scherrer , Jo Vliegen , Arish Sateesan , Hsu-Chun Hsiao , Nele Mentens , Adrian Perrig

Detection of anomalies among a large number of processes is a fundamental task that has been studied in multiple research areas, with diverse applications spanning from spectrum access to cyber-security. Anomalous events are characterized…

信息论 · 计算机科学 2022-08-12 Benjamin Wolff , Tomer Gafni , Guy Revach , Nir Shlezinger , Kobi Cohen

Active search refers to the problem of efficiently locating targets in an unknown environment by actively making data-collection decisions, and has many applications including detecting gas leaks, radiation sources or human survivors of…

机器学习 · 计算机科学 2020-06-29 Ramina Ghods , Arundhati Banerjee , Jeff Schneider

Botnets, which consist of thousands of compromised machines, can cause significant threats to other systems by launching Distributed Denial of Service (SSoS) attacks, keylogging, and backdoors. In response to these threats, new effective…

人工智能 · 计算机科学 2010-07-05 Yousof Al-Hammadi , Uwe Aickelin