中文
相关论文

相关论文: HOLMES: Real-time APT Detection through Correlatio…

200 篇论文

Cloud environments face frequent DDoS threats due to centralized resources and broad attack surfaces. Modern cloud-native DDoS attacks further evolve rapidly and often blend multi-vector strategies, creating an operational dilemma:…

密码学与安全 · 计算机科学 2026-01-22 Haodong Chen , Ziheng Zhang , Jinghui Jiang , Qiang Su , Qiao Xiang

Advanced Persistent Threats (APTs) have created new security challenges for critical infrastructures due to their stealthy, dynamic, and adaptive natures. In this work, we aim to lay a game-theoretic foundation by establishing a multi-stage…

计算机科学与博弈论 · 计算机科学 2018-09-10 Linan Huang , Quanyan Zhu

Statistical approaches to cyber-security involve building realistic probability models of computer network data. In a data pre-processing phase, separating automated events from those caused by human activity should improve statistical…

应用统计 · 统计学 2017-07-04 Matthew Price-Williams , Nick Heard , Melissa Turcotte

Advanced persistent threats (APT) combine a variety of different attack forms ranging from social engineering to technical exploits. The diversity and usual stealthiness of APT turns them into a central problem of contemporary practical…

密码学与安全 · 计算机科学 2022-05-03 Stefan Rass , Sandra König , Stefan Schauer

Distributed Denial of Service (DDoS) attacks have become more prominent recently, both in frequency of occurrence, as well as magnitude. Such attacks render key Internet resources unavailable and disrupt its normal operation. It is…

密码学与安全 · 计算机科学 2014-12-22 Michael Kallitsis , Stilian Stoev , George Michailidis

With frequently evolving Advanced Persistent Threats (APTs) in cyberspace, traditional security solutions approaches have become inadequate for threat hunting for organizations. Moreover, SOC (Security Operation Centers) analysts are often…

Intrusion detection systems perform post-compromise detection of security breaches whenever preventive measures such as firewalls do not avert an attack. However, these systems raise a vast number of alerts that must be analysed and triaged…

密码学与安全 · 计算机科学 2025-01-22 Herbert Maosa , Karim Ouazzane , Mohamed Chahine Ghanem

Cyber attacks targeting Industrial Control Systems (ICS) have become increasingly sophisticated and hard to identify. Detecting such attacks requires integrating low-level behavioral cues with high-level semantic interpretation, a…

密码学与安全 · 计算机科学 2026-04-07 Konstantinos E. Kampourakis , Vasileios Gkioulos , Sokratis Katsikas

As our cities and communities become smarter, the systems that keep us safe, such as traffic control centers, emergency response networks, and public transportation, also become more complex. With this complexity comes a greater risk of…

密码学与安全 · 计算机科学 2026-03-16 Sharif Noor Zisad , Ragib Hasan

Prefix hijacking is a common phenomenon in the Internet that often causes routing problems and economic losses. In this demo, we propose ARTEMIS, a tool that enables network administrators to detect and mitigate prefix hijacking incidents,…

网络与互联网体系结构 · 计算机科学 2017-06-27 Gavriil Chaviaras , Petros Gigis , Pavlos Sermpezis , Xenofontas Dimitropoulos

Bot detection using machine learning (ML), with network flow-level features, has been extensively studied in the literature. However, existing flow-based approaches typically incur a high computational overhead and do not completely capture…

密码学与安全 · 计算机科学 2019-02-25 Abbas Abou Daya , Mohammad A. Salahuddin , Noura Limam , Raouf Boutaba

Peer-to-peer (P2P) botnets have become one of the major threats in network security for serving as the fundamental infrastructure for various cyber-crimes. More challenges are involved in the problem of detecting P2P botnets, despite a few…

密码学与安全 · 计算机科学 2018-11-15 Di Zhuang , J. Morris Chang

Signature-based botnet detection methods identify botnets by recognizing Command and Control (C\&C) traffic and can be ineffective for botnets that use new and sophisticate mechanisms for such communications. To address these limitations,…

社会与信息网络 · 计算机科学 2015-03-10 Jing Wang , Ioannis Ch. Paschalidis

This paper is devoted to measuring the security of cyber networks under advanced persistent threats (APTs). First, an APT-based cyber attack-defense process is modeled as an individual-level dynamical system. Second, the dynamic model is…

密码学与安全 · 计算机科学 2017-07-13 Lu-Xing Yang , Pengdeng Li , Xiaofan Yang , Luosheng Wen , Yingbo Wu , Yuan Yan Tang

Threat actors can be persistent, motivated and agile, and leverage a diversified and extensive set of tactics and techniques to attain their goals. In response to that, defenders establish threat intelligence programs to stay…

密码学与安全 · 计算机科学 2021-03-30 Vasileios Mavroeidis , Audun Jøsang

Cyber-physical-social systems (CPSSs) have emerged in many applications over recent decades, requiring increased attention to security concerns. The rise of sophisticated threats like Advanced Persistent Threats (APTs) makes ensuring…

密码学与安全 · 计算机科学 2025-01-07 Saba Fathi Rabooki , Bowen Li , Falih Gozi Febrinanto , Ciyuan Peng , Elham Naghizade , Fengling Han , Feng Xia

The increase in scale of cyber networks and the rise in sophistication of cyber-attacks have introduced several challenges in intrusion detection. The primary challenge is the requirement to detect complex multi-stage attacks in realtime by…

密码学与安全 · 计算机科学 2023-02-01 Yahya Javed , Mosab A. Khayat , Ali A. Elghariani , Arif Ghafoor

As the complexity and destructiveness of Advanced Persistent Threat (APT) increase, there is a growing tendency to identify a series of actions undertaken to achieve the attacker's target, called attack investigation. Currently, analysts…

密码学与安全 · 计算机科学 2024-05-07 Jie Ying , Tiantian Zhu , Wenrui Cheng , Qixuan Yuan , Mingjun Ma , Chunlin Xiong , Tieming Chen , Mingqi Lv , Yan Chen

The ability to quickly and accurately detect anomalous structure within data sequences is an inference challenge of growing importance. This work extends recently proposed post-hoc (offline) anomaly detection methodology to the sequential…

统计方法学 · 统计学 2020-09-16 Alexander T. M. Fisch , Lawrence Bardwell , Idris A. Eckley

Large Language Models (LLMs) often generate incorrect or unsupported content, known as hallucinations. Existing detection methods rely on heuristics or simple models over isolated computational traces such as activations, or attention maps.…

机器学习 · 计算机科学 2025-09-30 Fabrizio Frasca , Guy Bar-Shalom , Yftah Ziser , Haggai Maron