arrow
Return

Event Log Correlation for Multi-Step Attack Detection

delete2025-11-30
delete0
delete
OA
AI
S
Syed Usman Shaukat *
S
Saad Khan
S
Simon Parkinson
DOI:10.1002/spy2.70151delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Event log correlation (ELC) is central to detecting multi-step attacks (MSAD) that unfold across heterogeneous systems and long time horizons. This review synthesises ELC families-mining/sequence, graph learning, provenance/causal correlation, and hybrid LLM-assisted approaches-through an MSAD-first lens that ties methods to attack stages and datasets. We report operational metrics (false-alarm reduction, detection time, throughput/storage) and classifier metrics (Accuracy/F1) as the authors present them, enabling fair comparison across 2025 works. Compared with prior surveys, we contribute a challenge mitigation map (false positives, latency/throughput, heterogeneity), a 2025-only section covering NDSS/USENIX/Neurocomputing studies and a recent Graph Convolutional Network (GCN) article (Multi dataset, Multi-family detection pipeline), and a roadmap spanning mining, graph, provenance/causal, and LLM-assisted correlation for scalable, real-time deployments. We also provide an attack-coverage matrix and a machine-readable extraction (8 papers 15+ fields) to support reproducible synthesis and practitioner adoption.
Keywords:
APT detection
event log correlation
event log correlation challenges
graph-based security analytics
multi-step attack detection
real-time intrusion detection
security log analysis
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

S
Security and Privacy
IF:
2.1
Papers:
126
Citations:
717

Organization

U
university of huddersfield
Scholars:
607
Papers: 306
Citations: 0
Cited Papers

Cited Papers

Defender Policy Evaluation and Resource Allocation With MITRE ATT&CK Evaluations Data
err2023-05-01
err7
errOAAI
errOutkin, Alexander V.; Schulz, Patricia V.; Schulz, Timothy; Tarman, Thomas D.; Pinar, Ali
errShare
errSave
ASTR: Transformer-based Alert-to-Stage Translator for multi-stage attack detection
err2025-06-01
err0
PREAI
errMa, Wei; Hou, Yunyun; Sui, Aina; Jian, Pengpeng
errShare
errSave
APT Behaviors Detection Based on Email Business Scenarios
err2021-10-01
err0
PREAI
errBai,Bo; Feng,Yun; Liu,Baoxu; Wang,Xutong; Liu,Jiaxi; Liu,Qingyue; Liu,Qixu; Zhao,Shuang
errShare
errSave
Event Log Preprocessing for Process Mining: A Review
err2021-11-10
err0
errOAAI
errHeidy M. Marin-Castro; Edgar Tello-Leal
errShare
errSave
researcher View more