Skip to main content

DeepCASE: Semi-Supervised Contextual Analysis of Security Events

Project description

DeepCASE

This repository contains the code for DeepCASE by the authors of the IEEE S&P DeepCASE [1] paper [PDF]. Please cite DeepCASE when using it in academic publications. This main branch provides DeepCASE as an out of the box tool. For the original experiments from the paper, please checkout the sp branch.

Introduction

DeepCASE introduces a semi-supervised approach for the contextual analysis of security events. This approach automatically finds correlations in sequences of security events and clusters these correlated sequences. The clusters of correlated sequences are then shown to security operators who can set policies for each sequence. Such policies can ignore sequences of unimportant events, pass sequences to a human operator for further inspection, or (in the future) automatically trigger response mechanisms. The main contribution of this work is to reduce the number of manual inspection security operators have to perform on the vast amounts of security events that they receive.

Documentation

We provide an extensive documentation including installation instructions and reference at deepcase.readthedocs.io.

References

[1] van Ede, T., Aghakhani, H., Spahn, N., Bortolameotti, R., Cova, M., Continella, A., van Steen, M., Peter, A., Kruegel, C. & Vigna, G. (2022, May). DeepCASE: Semi-Supervised Contextual Analysis of Security Events. In 2022 Proceedings of the IEEE Symposium on Security and Privacy (S&P). IEEE.

Bibtex

@inproceedings{vanede2020deepcase,
  title={{DeepCASE: Semi-Supervised Contextual Analysis of Security Events}},
  author={van Ede, Thijs and Aghakhani, Hojjat and Spahn, Noah and Bortolameotti, Riccardo and Cova, Marco and Continella, Andrea and van Steen, Maarten and Peter, Andreas and Kruegel, Christopher and Vigna, Giovanni},
  booktitle={Proceedings of the IEEE Symposium on Security and Privacy (S&P)},
  year={2022},
  organization={IEEE}
}

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

deepcase-1.0.1.tar.gz (661.7 kB view details)

Uploaded Source

Built Distribution

deepcase-1.0.1-py3-none-any.whl (37.6 kB view details)

Uploaded Python 3

File details

Details for the file deepcase-1.0.1.tar.gz.

File metadata

  • Download URL: deepcase-1.0.1.tar.gz
  • Upload date:
  • Size: 661.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.4.1 importlib_metadata/3.7.3 pkginfo/1.7.1 requests/2.25.1 requests-toolbelt/0.9.1 tqdm/4.56.0 CPython/3.8.10

File hashes

Hashes for deepcase-1.0.1.tar.gz
Algorithm Hash digest
SHA256 758e56540feef8085eae96ce89c8b03efa1307088e41fa570ff6f9eb47de1c50
MD5 4393fcd26894addce45588c6f5d9c71a
BLAKE2b-256 be4e9cdc00146e529dd7a63bdddae210e8f7d3166086836e696e2ad226f9f971

See more details on using hashes here.

File details

Details for the file deepcase-1.0.1-py3-none-any.whl.

File metadata

  • Download URL: deepcase-1.0.1-py3-none-any.whl
  • Upload date:
  • Size: 37.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.4.1 importlib_metadata/3.7.3 pkginfo/1.7.1 requests/2.25.1 requests-toolbelt/0.9.1 tqdm/4.56.0 CPython/3.8.10

File hashes

Hashes for deepcase-1.0.1-py3-none-any.whl
Algorithm Hash digest
SHA256 375883efafd529e9379986f8555a074b2b40f9745f4771890d29f9f5e4c0fc87
MD5 78a06e8c11f4b31a000d7598642c8465
BLAKE2b-256 238d9ca8768209baf1fa655562405457c740c1a4e4b8e627062c8040f6a6da4c

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page