DeepCASE: Semi-Supervised Contextual Analysis of Security Events
Project description
DeepCASE
This repository contains the code for DeepCASE by the authors of the IEEE S&P DeepCASE [1] paper [PDF].
Please cite DeepCASE when using it in academic publications. This main
branch provides DeepCASE as an out of the box tool. For the original experiments from the paper, please checkout the sp
branch.
Introduction
DeepCASE introduces a semi-supervised approach for the contextual analysis of security events. This approach automatically finds correlations in sequences of security events and clusters these correlated sequences. The clusters of correlated sequences are then shown to security operators who can set policies for each sequence. Such policies can ignore sequences of unimportant events, pass sequences to a human operator for further inspection, or (in the future) automatically trigger response mechanisms. The main contribution of this work is to reduce the number of manual inspection security operators have to perform on the vast amounts of security events that they receive.
Documentation
We provide an extensive documentation including installation instructions and reference at deepcase.readthedocs.io.
References
[1] van Ede, T., Aghakhani, H., Spahn, N., Bortolameotti, R., Cova, M., Continella, A., van Steen, M., Peter, A., Kruegel, C. & Vigna, G. (2022, May). DeepCASE: Semi-Supervised Contextual Analysis of Security Events. In 2022 Proceedings of the IEEE Symposium on Security and Privacy (S&P). IEEE.
Bibtex
@inproceedings{vanede2020deepcase,
title={{DeepCASE: Semi-Supervised Contextual Analysis of Security Events}},
author={van Ede, Thijs and Aghakhani, Hojjat and Spahn, Noah and Bortolameotti, Riccardo and Cova, Marco and Continella, Andrea and van Steen, Maarten and Peter, Andreas and Kruegel, Christopher and Vigna, Giovanni},
booktitle={Proceedings of the IEEE Symposium on Security and Privacy (S&P)},
year={2022},
organization={IEEE}
}
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file deepcase-0.0.1.tar.gz
.
File metadata
- Download URL: deepcase-0.0.1.tar.gz
- Upload date:
- Size: 659.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/3.4.1 importlib_metadata/3.7.3 pkginfo/1.7.1 requests/2.25.1 requests-toolbelt/0.9.1 tqdm/4.56.0 CPython/3.8.10
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | d52899203a38c06a90cf7316955ed046021b5452142610d3f69be6fd8f1f229c |
|
MD5 | 55ed87960a49e9877b1cdd3192effe12 |
|
BLAKE2b-256 | c14d376140f6c18f8192b321eb659aa38ace64336ad3be160a326dcc029fb163 |
File details
Details for the file deepcase-0.0.1-py3-none-any.whl
.
File metadata
- Download URL: deepcase-0.0.1-py3-none-any.whl
- Upload date:
- Size: 34.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/3.4.1 importlib_metadata/3.7.3 pkginfo/1.7.1 requests/2.25.1 requests-toolbelt/0.9.1 tqdm/4.56.0 CPython/3.8.10
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | bf44a22ed312f7dd67cbdd5650baddc2520016fe3d2be8480f79a7b0de0c5ce6 |
|
MD5 | 777999fb2dc516557dd7d6d41bdf4b58 |
|
BLAKE2b-256 | 6774123d0f42b623aed99df21ee9795006a068bf590afa2dfd2df5145b715348 |