Pretražite po imenu i prezimenu autora, mentora, urednika, prevoditelja

Napredna pretraga

Pregled bibliografske jedinice broj: 1085937

Systematic Review and Quantitative Comparison of Cyberattack Scenario Detection and Projection


Kovačević, Ivan; Groš, Stjepan; Slovenec, Karlo
Systematic Review and Quantitative Comparison of Cyberattack Scenario Detection and Projection // Electronics, 9(10) (2020), 1722, 32 doi:10.3390/electronics9101722 (međunarodna recenzija, članak, znanstveni)


CROSBI ID: 1085937 Za ispravke kontaktirajte CROSBI podršku putem web obrasca

Naslov
Systematic Review and Quantitative Comparison of Cyberattack Scenario Detection and Projection

Autori
Kovačević, Ivan ; Groš, Stjepan ; Slovenec, Karlo

Izvornik
Electronics (2079-9292) 9(10) (2020); 1722, 32

Vrsta, podvrsta i kategorija rada
Radovi u časopisima, članak, znanstveni

Ključne riječi
targeted attacks ; attack scenario ; intrusion detection ; alert correlation ; cyber situational awareness ; attack projection

Sažetak
Intrusion Detection Systems (IDSs) automatically analyze event logs and network traffic in order to detect malicious activity and policy violations. Because IDSs have a large number of false positives and false negatives and the technical nature of their alerts requires a lot of manual analysis, the researchers proposed approaches that automate the analysis of alerts to detect large-scale attacks and predict the attacker’s next steps. Unfortunately, many such approaches use unique datasets and success metrics, making comparison difficult. This survey provides an overview of the state of the art in detecting and projecting cyberattack scenarios, with a focus on evaluation and the corresponding metrics. Representative papers are collected while using Google Scholar and Scopus searches. Mutually comparable success metrics are calculated and several comparison tables are provided. Our results show that commonly used metrics are saturated on popular datasets and cannot assess the practical usability of the approaches. In addition, approaches with knowledge bases require constant maintenance, while data mining and ML approaches depend on the quality of available datasets, which, at the time of writing, are not representative enough to provide general knowledge regarding attack scenarios, so more emphasis needs to be placed on researching the behavior of attackers.

Izvorni jezik
Engleski

Znanstvena područja
Računarstvo



POVEZANOST RADA


Ustanove:
Fakultet elektrotehnike i računarstva, Zagreb

Profili:

Avatar Url Ivan Kovačević (autor)

Avatar Url Karlo Slovenec (autor)

Avatar Url Stjepan Groš (autor)

Poveznice na cjeloviti tekst rada:

doi www.mdpi.com

Citiraj ovu publikaciju:

Kovačević, Ivan; Groš, Stjepan; Slovenec, Karlo
Systematic Review and Quantitative Comparison of Cyberattack Scenario Detection and Projection // Electronics, 9(10) (2020), 1722, 32 doi:10.3390/electronics9101722 (međunarodna recenzija, članak, znanstveni)
Kovačević, I., Groš, S. & Slovenec, K. (2020) Systematic Review and Quantitative Comparison of Cyberattack Scenario Detection and Projection. Electronics, 9(10), 1722, 32 doi:10.3390/electronics9101722.
@article{article, author = {Kova\v{c}evi\'{c}, Ivan and Gro\v{s}, Stjepan and Slovenec, Karlo}, year = {2020}, pages = {32}, DOI = {10.3390/electronics9101722}, chapter = {1722}, keywords = {targeted attacks, attack scenario, intrusion detection, alert correlation, cyber situational awareness, attack projection}, journal = {Electronics}, doi = {10.3390/electronics9101722}, volume = {9(10)}, issn = {2079-9292}, title = {Systematic Review and Quantitative Comparison of Cyberattack Scenario Detection and Projection}, keyword = {targeted attacks, attack scenario, intrusion detection, alert correlation, cyber situational awareness, attack projection}, chapternumber = {1722} }
@article{article, author = {Kova\v{c}evi\'{c}, Ivan and Gro\v{s}, Stjepan and Slovenec, Karlo}, year = {2020}, pages = {32}, DOI = {10.3390/electronics9101722}, chapter = {1722}, keywords = {targeted attacks, attack scenario, intrusion detection, alert correlation, cyber situational awareness, attack projection}, journal = {Electronics}, doi = {10.3390/electronics9101722}, volume = {9(10)}, issn = {2079-9292}, title = {Systematic Review and Quantitative Comparison of Cyberattack Scenario Detection and Projection}, keyword = {targeted attacks, attack scenario, intrusion detection, alert correlation, cyber situational awareness, attack projection}, chapternumber = {1722} }

Časopis indeksira:


  • Current Contents Connect (CCC)
  • Web of Science Core Collection (WoSCC)
    • Science Citation Index Expanded (SCI-EXP)
    • Arts & Humanities Citation Index (A&HCI)
    • SCI-EXP, SSCI i/ili A&HCI
    • Emerging Sources Citation Index (ESCI)
  • Scopus


Citati:





    Contrast
    Increase Font
    Decrease Font
    Dyslexic Font