Global ETD Search

Search theses and dissertations gathered from participating repositories worldwide. Every result links back to the library that holds it. No account is needed.

Results

Showing 1 to 5 of 5 for “"Alert Correlation"”.

  1. Intrusion Detection for Cyber-Physical Attacks in Cyber-Manufacturing System

    … in terms of intrusion detection algorithms, and alert correlation methods. The attacks are further broken down into a taxonomy covering four dimensions with over thirty attack scenarios to comprehensively study and simulate cyber-physical attacks. </p> <p>A new intrusion detection and correlation

    syracuse-diss Repository record for Intrusion Detection for Cyber-Physical Attacks in Cyber-Manufacturing System (opens in a new tab)

  2. Mining intrusion detection alert logs to minimise false positives & gain attack insight

    … Firstly, we explore how the quality of intrusion alert logs can be improved by eliminating the large volume of false positive alerts contained in intrusion detection logs. We investigate probabilistic alert correlation, an alternative to traditional rule based correlation approaches. We …

    city-london Repository record for Mining intrusion detection alert logs to minimise false positives & gain attack insight (opens in a new tab)

  3. Distress detection

    … or produce impractical amounts of daily false alerts. Advances in intrusion detection techniques have so far only partly alleviated the problem as they are still tied to existing methods. This thesis proposes Distress Detection (DD), a detection method providing novel web attack resilience …

    strathclyde Repository record for Distress detection (opens in a new tab)

  4. From Alerts to Defense: Towards Building Adaptive Frameworks for Detection, Correlation, and Response

    Security Operation Centers work under sustained alert load and must investigate a significant number of alerts daily, and must do so with confidence. This dissertation presents three frameworks that operate on commodity audit telemetry and help analysts correlate activity, investigate alerts with …

    uic

  5. Statistical anomaly denial of service and reconnaissance intrusion detection

    … Activity Profiler (RAP) and the Reconnaissance Alert Correlater (RAC). The RAP is a session-oriented module capable of detecting stealthy scanning and probing attacks, while the RAG is an alert-correlation module that fuses the RAP alerts into attack scenarios and discovers the distributed …

    njit Repository record for Statistical anomaly denial of service and reconnaissance intrusion detection (opens in a new tab)