Threat Alert Prioritization Using Isolation Forest and Stacked Auto Encoder With Day-Forward-Chaining Analysis
Security Incident and Event Manager (SIEM) is a security management approach designed to identify possible threats within a real-time enterprise environment. The main challenge for SIEM is to find critical security incidents among a huge number of less critical alerts coming from separate security p...
Main Authors: | Muhamad Erza Aminanto, Tao Ban, Ryoichi Isawa, Takeshi Takahashi, Daisuke Inoue |
---|---|
Format: | Article |
Language: | English |
Published: |
IEEE
2020-01-01
|
Series: | IEEE Access |
Subjects: | |
Online Access: | https://ieeexplore.ieee.org/document/9276411/ |
Similar Items
-
ARCA - Alerts root cause analysis framework
by: Melo, Daniel Araújo
Published: (2015) -
Hidden Markov models and alert correlations for the prediction of advanced persistent threats
by: Ghafir, Ibrahim, et al.
Published: (2020) -
Hidden Markov Models and Alert Correlations for the Prediction of Advanced Persistent Threats
by: Ibrahim Ghafir, et al.
Published: (2019-01-01) -
Prioritization and Alert Fusion in Distributed IoT Sensors Using Kademlia Based Distributed Hash Tables
by: Mansoor Nasir, et al.
Published: (2020-01-01) -
A Fuzzy-logic based Alert Prioritization Engine for IDSs: Architecture and Configuration
by: Alsubhi, Khalid
Published: (2008)