中文
相关论文

相关论文: SIERRA: Ranking Anomalous Activities in Enterprise…

200 篇论文

Security Information and Event Management (SIEM) systems are essential for large enterprises to monitor their IT infrastructure by ingesting and analyzing millions of logs and events daily. Security Operations Center (SOC) analysts are…

密码学与安全 · 计算机科学 2026-01-01 Md Hasan Saju , Austin Page , Akramul Azim , Jeff Gardiner , Farzaneh Abazari , Frank Eargle

Cyber incidents can have a wide range of cause from a simple connection loss to an insistent attack. Once a potential cyber security incidents and system failures have been identified, deciding how to proceed is often complex. Especially,…

计算机与社会 · 计算机科学 2020-07-16 Sandro Passarelli , Cem Gündogan , Lars Stiemert , Matthias Schopp , Peter Hillmann

Critical Infrastructure Protection is one of the main challenges of last years. Security Information and Event Management (SIEM) systems are widely used for coping with this challenge. However, they currently present several limitations…

密码学与安全 · 计算机科学 2014-05-14 Alessia Garofalo , Cesario Di Sarno , Ilaria Matteucci , Marco Vallini , Valerio Formicola

Analysis of an organization's computer network activity is a key component of early detection and mitigation of insider threat, a growing concern for many organizations. Raw system logs are a prototypical example of streaming data that can…

神经与进化计算 · 计算机科学 2017-12-19 Aaron Tuor , Samuel Kaplan , Brian Hutchinson , Nicole Nichols , Sean Robinson

Enterprises are constantly under attack from sophisticated adversaries. These adversaries use a variety of techniques to first gain access to the enterprise, then spread laterally inside its networks, establish persistence, and finally…

密码学与安全 · 计算机科学 2024-06-14 Sumanth Rao

On the path to establishing a global cybersecurity framework where each enterprise shares information about malicious behavior, an important question arises. How can a machine learning representation characterizing a cyber attack on one…

机器学习 · 计算机科学 2019-07-26 Casey Kneale , Kolia Sadeghi

Security incident analysis (SIA) poses a major challenge for security operations centers, which must manage overwhelming alert volumes, large and diverse data sources, complex toolchains, and limited analyst expertise. These difficulties…

密码学与安全 · 计算机科学 2026-03-09 Sourov Jajodia , Madeena Sultana , Suryadipta Majumdar , Adrian Taylor , Grant Vandenberghe

Technology evolves quickly. Low-cost and ready-to-connect devices are designed to provide new services and applications. Smart grids or smart healthcare systems are some examples of these applications, all of which are in the context of…

密码学与安全 · 计算机科学 2021-12-07 Roberto Magán-Carrión , José Camacho , Gabriel Maciá-Fernández , Ángel Ruíz-Zafra

Securing enterprise networks presents challenges in terms of both their size and distributed structure. Data required to detect and characterize malicious activities may be diffused and may be located across network and endpoint devices.…

Operational network data, management data such as customer care call logs and equipment system logs, is a very important source of information for network operators to detect problems in their networks. Unfortunately, there is lack of…

网络与互联网体系结构 · 计算机科学 2012-03-12 Chi-Yao Hong , Matthew Caesar , Nick Duffield , Jia Wang

Enterprise networks are one of the major targets for cyber attacks due to the vast amount of sensitive and valuable data they contain. A common approach to detecting attacks in the enterprise environment relies on modeling the behavior of…

密码学与安全 · 计算机科学 2022-06-14 Enes Altinisik , Husrev Taha Sencar , Mohamed Nabeel , Issa Khalil , Ting Yu

In this paper, we introduce BINet, a neural network architecture for real-time multi-perspective anomaly detection in business process event logs. BINet is designed to handle both the control flow and the data perspective of a business…

人工智能 · 计算机科学 2019-11-05 Timo Nolle , Stefan Luettgen , Alexander Seeliger , Max Mühlhäuser

This paper describes the architecture and the fundamental methodology of an anomaly detector, which by continuously monitoring Simple Network Management Protocol data and by processing it as complex-events, is able to timely recognize…

密码学与安全 · 计算机科学 2021-06-29 Massimiliano Leone Itria , Enrico Schiavone , Nicola Nostro

Large network logs, recording multivariate time series generated from heterogeneous devices and sensors in a network, can often reveal important information about abnormal activities, such as network intrusions and device malfunctions.…

机器学习 · 计算机科学 2025-06-19 Yijun Lin , Yao-Yi Chiang

Hacker forums provide critical early warning signals for emerging cybersecurity threats, but extracting actionable intelligence from their unstructured and noisy content remains a significant challenge. This paper presents an unsupervised…

密码学与安全 · 计算机科学 2025-07-15 Yasir Ech-Chammakhy , Anas Motii , Anass Rabii , Jaafar Chbili

To assure cyber security of an enterprise, typically SIEM (Security Information and Event Management) system is in place to normalize security event from different preventive technologies and flag alerts. Analysts in the security operation…

密码学与安全 · 计算机科学 2018-01-03 Wangyan Feng , Shuning Wu , Xiaodan Li , Kevin Kunkle

This paper presents HURRA, a system that aims to reduce the time spent by human operators in the process of network troubleshooting. To do so, it comprises two modules that are plugged after any anomaly detection algorithm: (i) a first…

人工智能 · 计算机科学 2021-07-26 Jose M. Navarro , Dario Rossi

Cyberattacks have grown into a major risk for organizations, with common consequences being data theft, sabotage, and extortion. Since preventive measures do not suffice to repel attacks, timely detection of successful intruders is crucial…

密码学与安全 · 计算机科学 2023-12-21 Rafael Uetz , Marco Herzog , Louis Hackländer , Simon Schwarz , Martin Henze

Anomaly detection in event logs is a promising approach for intrusion detection in enterprise networks. By building a statistical model of usual activity, it aims to detect multiple kinds of malicious behavior, including stealthy tactics,…

密码学与安全 · 计算机科学 2022-06-29 Corentin Larroche , Johan Mazel , Stephan Clémençon

Researchers have typically concentrated on analyzing what happens internally in a complex network and using this to distinguish between nodes. However, there has been less effort towards comparing between different networks. In this paper,…

社会与信息网络 · 计算机科学 2015-03-03 Zeynab Bahrami Bidoni , Roy George
‹ 上一页 1 2 3 10 下一页 ›