Return
Event Log Correlation for Multi-Step Attack Detection
DOI:10.1002/spy2.70151.png)
Abstract
En 中文
Event log correlation (ELC) is central to detecting multi-step attacks (MSAD) that unfold across heterogeneous systems and long time horizons. This review synthesises ELC families-mining/sequence, graph learning, provenance/causal correlation, and hybrid LLM-assisted approaches-through an MSAD-first lens that ties methods to attack stages and datasets. We report operational metrics (false-alarm reduction, detection time, throughput/storage) and classifier metrics (Accuracy/F1) as the authors present them, enabling fair comparison across 2025 works. Compared with prior surveys, we contribute a challenge mitigation map (false positives, latency/throughput, heterogeneity), a 2025-only section covering NDSS/USENIX/Neurocomputing studies and a recent Graph Convolutional Network (GCN) article (Multi dataset, Multi-family detection pipeline), and a roadmap spanning mining, graph, provenance/causal, and LLM-assisted correlation for scalable, real-time deployments. We also provide an attack-coverage matrix and a machine-readable extraction (8 papers 15+ fields) to support reproducible synthesis and practitioner adoption.
Keywords:
APT detection
event log correlation
event log correlation challenges
graph-based security analytics
multi-step attack detection
real-time intrusion detection
security log analysis
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
S
IF:
2.1
Papers:
126
Citations:
717
Organization
Cited Papers
ASTR: Transformer-based Alert-to-Stage Translator for multi-stage attack detection
NEUROCOMPUTING
IF6.5

