Methods of Intelligent System Event Analysis for Multistep Cyberattack Detection Using Knowledge Bases


연구 분야: Safety



학회: Scientific and Technical Information Processing


초록

This study presents a classification and comparative analysis of intelligent system event analysis methods for detecting multistep cyberattacks, which are a set of sequential actions of one or more attackers pursuing a specific goal of intrusion. The paper analyzes approaches to the detection of multistep cyberattacks based on knowledge bases, such as expert rules and event scenarios (sequences). The considered approaches are analyzed by such criteria as the method for extracting knowledge about scenarios of system events and attacks, the scenario knowledge representation method, the security events analysis method, and the security problem requiring to be solved. The paper shows the main advantages and disadvantages of the approaches to detecting multistep cyberattacks as well as lines of possible research in this area.


Author Profile
I. V. Kotenko

St. Petersburg Federal Research Center of the Russian Academy of Sciences (SPb FRC RAS) 199178 St. Petersburg Russia

Russia
Author Profile
D. A. Levshun

St. Petersburg Federal Research Center of the Russian Academy of Sciences (SPb FRC RAS) 199178 St. Petersburg Russia

Russia

📄 논문 정보

발행 연도 2025년
인용수 0
출판 국가 Russia
사이트 Springer
좋아요 수 0

연관 논문 목록 (516건)