arrow
Return

Exploratory security analytics for anomaly detection

delete2016-02-01
delete14
delete
OA
AI
F
Fabio Pierazzi *
S
Sara Casolari
M
Michele Colajanni
M
Mirco Marchetti
DOI:10.1016/j.cose.2015.10.003delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
The huge number of alerts generated by network-based defense systems prevents detailed manual inspections of security events. Existing proposals for automatic alerts analysis work well in relatively stable and homogeneous environments, but in modem networks, that are characterized by extremely complex and dynamic behaviors, understanding which approaches can be effective requires exploratory data analysis and descriptive modeling. We propose a novel framework for automatically investigating temporal trends and patterns of security alerts with the goal of understanding whether and which anomaly detection approaches can be adopted for identifying relevant security events. Several examples referring to a real large network show that, despite the high intrinsic dynamism of the system, the proposed framework is able to extract relevant descriptive statistics that allow to determine the effectiveness of popular anomaly detection approaches on different alerts groups. (C) 2015 Elsevier Ltd. All rights reserved.
Keywords:
Security analytics
Network alerts
Temporal characterization
Time series analysis
Anomaly detection
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

U
universita di modena e reggio emilia
Scholars:
1.6W
Papers: 1.2W
Citations: 12