5 papers
Passive, Transparent, and Selective TLS Decryption for Network Security Monitoring
Florian Wilkens, Steffen Haas, Johanna Amann +1
Internet traffic is increasingly encrypted. While this protects the confidentiality and integrity of communication, it prevents network monitoring systems (NMS) and intrusion detec…
Multi-Stage Attack Detection via Kill Chain State Machines
Florian Wilkens, Felix Ortmann, Steffen Haas +2
Today, human security analysts collapse under the sheer volume of alerts they have to triage during investigations. The inability to cope with this load, coupled with a high false…
Towards Flexible Security Testing of OT Devices
Florian Wilkens, Samuel Botzler, Julia Curts +6
In the factory of the future traditional and formerly isolated Operational Technology (OT) hardware will become connected with all kinds of networks. This leads to more complex sec…
Scan Correlation -- Revealing distributed scan campaigns
Steffen Haas, Florian Wilkens, Mathias Fischer
Public networks are exposed to port scans from the Internet. Attackers search for vulnerable services they can exploit. In large scan campaigns, attackers often utilize different m…
Efficient Attack Correlation and Identification of Attack Scenarios based on Network-Motifs
Steffen Haas, Florian Wilkens, Mathias Fischer
An Intrusion Detection System (IDS) to secure computer networks reports indicators for an attack as alerts. However, every attack can result in a multitude of IDS alerts that need…