Passer à la navigation principale Passer à la recherche Passer au contenu principal

DAEMON: Dynamic Auto-encoders for Contextualised Anomaly Detection Applied to Security MONitoring

  • IRISA
  • Airbus Cyber Security

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

Résumé

The slow adoption rate of machine learning-based methods for novel attack detection by Security Operation Centers (SOC) analysts can be partly explained by their lack of data science expertise and the insufficient explainability of the results provided by these approaches. In this paper, we present an anomaly-based detection method that fuses events coming from heterogeneous sources into sets describing the same phenomenons and relies on a deep auto-encoder model to highlight anomalies and their context. To implicate security analysts and benefit from their expertise, we focus on limiting the need of data science knowledge during the configuration phase. Results on a lab environment, monitored using off-the-shelf tools, show good detection performances on several attack scenarios (F1 score ≈ 0.9 ), and eases the investigation of anomalies by quickly finding similar anomalies through clustering.

langue originaleAnglais
titreICT Systems Security and Privacy Protection - 37th IFIP TC 11 International Conference, SEC 2022, Proceedings
rédacteurs en chefWeizhi Meng, Simone Fischer-Hübner, Christian D. Jensen
EditeurSpringer Science and Business Media Deutschland GmbH
Pages53-69
Nombre de pages17
ISBN (imprimé)9783031069741
Les DOIs
étatPublié - 1 janv. 2022
Evénement37th IFIP International Conference on ICT Systems Security and Privacy Protection, SEC 2022 - Copenhagen, Danemark
Durée: 13 juin 202215 juin 2022

Série de publications

NomIFIP Advances in Information and Communication Technology
Volume648 IFIP
ISSN (imprimé)1868-4238
ISSN (Electronique)1868-422X

Une conférence

Une conférence37th IFIP International Conference on ICT Systems Security and Privacy Protection, SEC 2022
Pays/TerritoireDanemark
La villeCopenhagen
période13/06/2215/06/22

Empreinte digitale

Examiner les sujets de recherche de « DAEMON: Dynamic Auto-encoders for Contextualised Anomaly Detection Applied to Security MONitoring ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation