4 citations · 5 across the 4 of their papers we have counts for
4 papers · 1 filter
How It's Made: Uncovering Detection Engineering Processes for Network Intrusion Detection Rules
Koen T. W. Teuwen, Emmanuele Zambon, Luca Allodi
Many Security Operations Centers rely on signature-based Network Intrusion Detection Systems like Suricata, yet detection rule engineering remains understudied. We investigate this…
On the Effect of Ruleset Tuning and Data Imbalance on Explainable Network Security Alert Classifications: a Case-Study on DeepCASE
Koen T. W. Teuwen, Sam Baggen, Emmanuele Zambon +1
Automation in Security Operations Centers (SOCs) plays a prominent role in alert classification and incident escalation. However, automated methods must be robust in the presence o…
Ruling the Unruly: Designing Effective, Low-Noise Network Intrusion Detection Rules for Security Operations Centers
Koen T. W. Teuwen, Tom Mulders, Emmanuele Zambon +1
Many Security Operations Centers (SOCs) today still heavily rely on signature-based Network Intrusion Detection Systems (NIDS) such as Suricata. The specificity of intrusion detect…
A Modular Approach to Automatic Cyber Threat Attribution using Opinion Pools
Koen T. W. Teuwen
Cyber threat attribution can play an important role in increasing resilience against digital threats. Recent research focuses on automating the threat attribution process and on in…