Threat Detection Through Correlation of Network Flows and Logs
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216224%3A14610%2F18%3A00106899" target="_blank" >RIV/00216224:14610/18:00106899 - isvavai.cz</a>
Result on the web
<a href="http://www.aims-conference.org/2018/AIMS-2018-Proceedings.pdf" target="_blank" >http://www.aims-conference.org/2018/AIMS-2018-Proceedings.pdf</a>
DOI - Digital Object Identifier
—
Alternative languages
Result language
angličtina
Original language name
Threat Detection Through Correlation of Network Flows and Logs
Original language description
A rising amount of mutually interconnected and communicating devices puts increasing demands on cybersecurity operators and their tools. With the rise of end-to-end encryption, it is becoming increasingly difficult to detect threats in network traffic. With such motivation, this Ph.D. proposal aims to find new methods for automatic detection of threats hiding in encrypted channels. The focus of the proposal is on correlating the data still available in the encrypted network flows with the data contained in the logs of network applications. Our research is in the initial phase and will contribute to a Ph.D. thesis in four years.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
—
OECD FORD branch
10200 - Computer and information sciences
Result continuities
Project
<a href="/en/project/VI20172020070" target="_blank" >VI20172020070: Research of Tools for Cyber Situational Awareness and Decision Support of CSIRT Teams in Protection of Critical Infrastructure</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Others
Publication year
2018
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
Proceedings of the 12th International Conference on Autonomous Infrastructure, Management and Security (AIMS 2018)
ISBN
9783903176126
ISSN
—
e-ISSN
—
Number of pages
5
Pages from-to
6-10
Publisher name
IFIP
Place of publication
Neuveden
Event location
Munich
Event date
Jun 4, 2018
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
—