中文
相关论文

相关论文: You Cannot Escape Me: Detecting Evasions of SIEM R…

200 篇论文

Intrusion Detection System or IDS is a software or hardware tool that repeatedly scans and monitors events that took place in a computer or a network. A set of rules are used by Signature based Network Intrusion Detection Systems or NIDS to…

密码学与安全 · 计算机科学 2014-11-26 Laxmi Lahoti , Chaitali Chandankhede , Debajyoti Mukhopadhyay

Over the recent years, IP and email spoofing gained much importance for security concerns due to the current changes in manipulating the system performance in different online environments. Intrusion Detection System (IDS) has been used to…

密码学与安全 · 计算机科学 2009-11-04 Al-Sammarraie Hosam , Adli Mustafa , Shakeel Ahmad , Merza Abbas

Network intrusion detection systems (NIDSs) play an important role in computer network security. There are several detection mechanisms where anomaly-based automated detection outperforms others significantly. Amid the sophistication and…

Despite all the advantages associated with Network Intrusion Detection Systems (NIDSs) that utilize machine learning (ML) models, there is a significant reluctance among cyber security experts to implement these models in real-world…

密码学与安全 · 计算机科学 2025-09-26 Ayush Kumar , Kar Wai Fok , Vrizlynn L. L. Thing

SIEM systems serve as a critical hub, employing rule-based logic to detect and respond to threats. Redundant or overlapping rules in SIEM systems lead to excessive false alerts, degrading analyst performance due to alert fatigue, and…

密码学与安全 · 计算机科学 2025-05-13 Akansha Shukla , Parth Atulbhai Gandhi , Yuval Elovici , Asaf Shabtai

Network intrusion detection is the problem of detecting unauthorised use of, or access to, computer systems over a network. Two broad approaches exist to tackle this problem: anomaly detection and misuse detection. An anomaly detection…

神经与进化计算 · 计算机科学 2012-08-03 Simon T. Powers , Jun He

Security Information and Event Management (SIEM) systems aggregate log data from heterogeneous sources to detect coordinated attacks. Traditional rule-based correlation engines struggle to classify multi-step web application attacks because…

密码学与安全 · 计算机科学 2026-05-14 Badr Alboushy , Assef Jafar , Mohamad Aljnidi , Mohamad Bashar Disoki , Aref Shaheed

Web request query strings (queries), which pass parameters to the referenced resource, are always manipulated by attackers to retrieve sensitive data and even take full control of victim web servers and web applications. However, existing…

密码学与安全 · 计算机科学 2018-01-12 Ying Dong , Yuqing Zhang

Recently, Provenance-based Intrusion Detection Systems (PIDSes) have been widely used for endpoint threat analysis. These studies can be broadly categorized into rule-based detection systems and learning-based detection systems. Among…

密码学与安全 · 计算机科学 2025-07-23 Wenrui Cheng , Tiantian Zhu , Shunan Jing , Jian-Ping Mei , Mingjun Ma , Jiaobo Jin , Zhengqiu Weng

An Intrusion Detection System (IDS) is a software that monitors a single or a network of computers for malicious activities (attacks) that are aimed at stealing or censoring information or corrupting network protocols. Most techniques used…

密码学与安全 · 计算机科学 2015-05-12 Mahdi Zamani , Mahnush Movahedi

Securing enterprise networks presents challenges in terms of both their size and distributed structure. Data required to detect and characterize malicious activities may be diffused and may be located across network and endpoint devices.…

Data centers play a key role in today's Internet. Cloud applications are mainly hosted on multi-tenant warehouse-scale data centers. Anomalies pose a serious threat to data centers' operations. If not controlled properly, a simple anomaly…

网络与互联网体系结构 · 计算机科学 2019-06-18 Ashkan Aghdai , Kang Xi , H. Jonathan Chao

Evolving attacks are a critical challenge for the long-term success of Network Intrusion Detection Systems (NIDS). The rise of these changing patterns has exposed the limitations of traditional network security methods. While…

密码学与安全 · 计算机科学 2025-06-10 Emilia Rivas , Sabrina Saika , Ahtesham Bakht , Aritran Piplai , Nathaniel D. Bastian , Ankit Shah

In corporations around the world, the topic of cybersecurity and information security is becoming increasingly important as the number of cyberattacks on themselves continues to grow. Nowadays, it is no longer just a matter of protecting…

密码学与安全 · 计算机科学 2024-06-21 Maximilian Rosenberg , Bettina Schneider , Christopher Scherb , Petra Maria Asprion

The increase in scale of cyber networks and the rise in sophistication of cyber-attacks have introduced several challenges in intrusion detection. The primary challenge is the requirement to detect complex multi-stage attacks in realtime by…

密码学与安全 · 计算机科学 2023-02-01 Yahya Javed , Mosab A. Khayat , Ali A. Elghariani , Arif Ghafoor

Machine learning models have been widely used in security applications such as intrusion detection, spam filtering, and virus or malware detection. However, it is well-known that adversaries are always trying to adapt their attacks to evade…

密码学与安全 · 计算机科学 2018-08-13 Fan Yang , Zhiyuan Chen

To assure cyber security of an enterprise, typically SIEM (Security Information and Event Management) system is in place to normalize security event from different preventive technologies and flag alerts. Analysts in the security operation…

密码学与安全 · 计算机科学 2018-01-03 Wangyan Feng , Shuning Wu , Xiaodan Li , Kevin Kunkle

Network Control Systems (NAC) have been used in many industrial processes. They aim to reduce the human factor burden and efficiently handle the complex process and communication of those systems. Supervisory control and data acquisition…

密码学与安全 · 计算机科学 2019-04-12 Hanan Hindy , David Brosset , Ethan Bayne , Amar Seeam , Xavier Bellekens

Malicious websites are a major cyber attack vector, and effective detection of them is an important cyber defense task. The main defense paradigm in this regard is that the defender uses some kind of machine learning algorithms to train a…

密码学与安全 · 计算机科学 2014-08-12 Li Xu , Zhenxin Zhan , Shouhuai Xu , Keyin Ye

An intrusion detection system framework using mobile agents is a layered framework mechanism designed to support heterogeneous network environments to identify intruders at its best. Traditional computer misuse detection techniques can…

网络与互联网体系结构 · 计算机科学 2010-07-15 N. Jaisankar , R. Saravanan , K. Durai Swamy
‹ 上一页 1 2 3 10 下一页 ›