activity
20192021
collaborators

5 papers

cs.CR2021

Passive, Transparent, and Selective TLS Decryption for Network Security Monitoring

Florian Wilkens, Steffen Haas, Johanna Amann +1

Internet traffic is increasingly encrypted. While this protects the confidentiality and integrity of communication, it prevents network monitoring systems (NMS) and intrusion detec…

cs.CR2021

Multi-Stage Attack Detection via Kill Chain State Machines

Florian Wilkens, Felix Ortmann, Steffen Haas +2

Today, human security analysts collapse under the sheer volume of alerts they have to triage during investigations. The inability to cope with this load, coupled with a high false…

cs.CR2020

Scan Correlation -- Revealing distributed scan campaigns

Steffen Haas, Florian Wilkens, Mathias Fischer

Public networks are exposed to port scans from the Internet. Attackers search for vulnerable services they can exploit. In large scan campaigns, attackers often utilize different m…

cs.CR2020

zeek-osquery: Host-Network Correlation for Advanced Monitoring and Intrusion Detection

Steffen Haas, Robin Sommer, Mathias Fischer

Intrusion Detection Systems (IDSs) can analyze network traffic for signs of attacks and intrusions. However, encrypted communication limits their visibility and sophisticated attac…

cs.CR2019

Efficient Attack Correlation and Identification of Attack Scenarios based on Network-Motifs

Steffen Haas, Florian Wilkens, Mathias Fischer

An Intrusion Detection System (IDS) to secure computer networks reports indicators for an attack as alerts. However, every attack can result in a multitude of IDS alerts that need…