首页> 外文期刊>ERCIM News >INDIC?TING – Automatically Detecting, Extracting, and Correlating Cyber Threat Intelligence from Raw Computer Log Data
【24h】

INDIC?TING – Automatically Detecting, Extracting, and Correlating Cyber Threat Intelligence from Raw Computer Log Data

机译:指示–从原始计算机日志数据中自动检测,提取和关联网络威胁情报

获取原文
       

摘要

“Cyber threat intelligence” is security-relevant information, often directly derived from cyber incidents that enables comprehensive protection against upcoming cyber-attacks. However, collecting and transforming the available low-level data into high-level threat intelligence is usually time-consuming and requires extensive manual work as well as in-depth domain knowledge. INDIC?TING supports this procedure by developing and applying machine learning algorithms that automatically detect anomalies in the monitored system behaviour, correlate affected events to generate multi-step attack models and aggregate them to generate usable threat intelligence.
机译:“网络威胁情报”是与安全相关的信息,通常直接从网络事件中获取,从而能够全面防御即将发生的网络攻击。但是,收集可用的低级数据并将其转换为高级威胁情报通常很耗时,并且需要大量的人工工作以及深入的领域知识。指示通过开发和应用机器学习算法来支持此过程,该算法可自动检测受监视系统行为中的异常,关联受影响的事件以生成多步攻击模型并将它们汇总以生成可用的威胁情报。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号