5 papers
AlertBERT: A noise-robust alert grouping framework for simultaneous cyber attacks
Lukas Karner, Max Landauer, Markus Wurzenberger +1
Automated detection of cyber attacks is a critical capability to counteract the growing volume and sophistication of cyber attacks. However, the high numbers of security alerts iss…
AttackMate: Realistic Emulation and Automation of Cyber Attack Scenarios Across the Kill Chain
Max Landauer, Wolfgang Hotwagner, Thorina Boenke +2
Adversary emulation tools facilitate scripting and automated execution of cyber attack chains, thereby reducing costs and manual expert effort required for security testing, cyber…
StealthCup: Realistic, Multi-Stage, Evasion-Focused CTF for Benchmarking IDS
Manuel Kern, Dominik Steffan, Felix Schuster +5
Intrusion Detection Systems (IDS) are critical to defending enterprise and industrial control environments, yet evaluating their effectiveness under realistic conditions remains an…
System Log Parsing with Large Language Models: A Review
Viktor Beck, Max Landauer, Markus Wurzenberger +2
Log data provides crucial insights for tasks like monitoring, root cause analysis, and anomaly detection. Due to the vast volume of logs, automated log parsing is essential to tran…
Towards Improving IDS Using CTF Events
Manuel Kern, Florian Skopik, Max Landauer +1
In cybersecurity, Intrusion Detection Systems (IDS) serve as a vital defensive layer against adversarial threats. Accurate benchmarking is critical to evaluate and improve IDS effe…