Contextual information fusion for intrusion detection: a survey and taxonomy

作者:Ahmed Aleroud, George Karabatis

摘要

Research in cyber-security has demonstrated that dealing with cyber-attacks is by no means an easy task. One particular limitation of existing research originates from the uncertainty of information that is gathered to discover attacks. This uncertainty is partly due to the lack of attack prediction models that utilize contextual information to analyze activities that target computer networks. The focus of this paper is a comprehensive review of data analytics paradigms for intrusion detection along with an overview of techniques that apply contextual information for intrusion detection. A new research taxonomy is introduced consisting of several dimensions of data mining techniques, which create attack prediction models. The survey reveals the need to use multiple categories of contextual information in a layered manner with consistent, coherent, and feasible evidence toward the correct prediction of cyber-attacks.

论文关键词:Context, Contextual information, Cyber-security, Netflows, Intrusion detection, Semantics

论文评审过程:

论文官网地址:https://doi.org/10.1007/s10115-017-1027-3