Sie befinden Sich nicht im Netzwerk der Universität Paderborn. Der Zugriff auf elektronische Ressourcen ist gegebenenfalls nur via VPN oder Shibboleth (DFN-AAI) möglich. mehr Informationen...
Ergebnis 22 von 457

Details

Autor(en) / Beteiligte
Titel
Systematic Review and Quantitative Comparison of Cyberattack Scenario Detection and Projection
Ist Teil von
  • Electronics (Basel), 2020-10, Vol.9 (10), p.1722
Ort / Verlag
Basel: MDPI AG
Erscheinungsjahr
2020
Link zum Volltext
Quelle
EZB Electronic Journals Library
Beschreibungen/Notizen
  • Intrusion Detection Systems (IDSs) automatically analyze event logs and network traffic in order to detect malicious activity and policy violations. Because IDSs have a large number of false positives and false negatives and the technical nature of their alerts requires a lot of manual analysis, the researchers proposed approaches that automate the analysis of alerts to detect large-scale attacks and predict the attacker’s next steps. Unfortunately, many such approaches use unique datasets and success metrics, making comparison difficult. This survey provides an overview of the state of the art in detecting and projecting cyberattack scenarios, with a focus on evaluation and the corresponding metrics. Representative papers are collected while using Google Scholar and Scopus searches. Mutually comparable success metrics are calculated and several comparison tables are provided. Our results show that commonly used metrics are saturated on popular datasets and cannot assess the practical usability of the approaches. In addition, approaches with knowledge bases require constant maintenance, while data mining and ML approaches depend on the quality of available datasets, which, at the time of writing, are not representative enough to provide general knowledge regarding attack scenarios, so more emphasis needs to be placed on researching the behavior of attackers.
Sprache
Englisch
Identifikatoren
ISSN: 2079-9292
eISSN: 2079-9292
DOI: 10.3390/electronics9101722
Titel-ID: cdi_doaj_primary_oai_doaj_org_article_dc6a23be56b049e78eafa43cb8f1c215

Weiterführende Literatur

Empfehlungen zum selben Thema automatisch vorgeschlagen von bX