3 papers
cs.CR2025
On the Effect of Ruleset Tuning and Data Imbalance on Explainable Network Security Alert Classifications: a Case-Study on DeepCASE
Koen T. W. Teuwen, Sam Baggen, Emmanuele Zambon +1
Automation in Security Operations Centers (SOCs) plays a prominent role in alert classification and incident escalation. However, automated methods must be robust in the presence o…
cs.CR2025
Ruling the Unruly: Designing Effective, Low-Noise Network Intrusion Detection Rules for Security Operations Centers
Koen T. W. Teuwen, Tom Mulders, Emmanuele Zambon +1
Many Security Operations Centers (SOCs) today still heavily rely on signature-based Network Intrusion Detection Systems (NIDS) such as Suricata. The specificity of intrusion detect…
cs.CR2024
A Modular Approach to Automatic Cyber Threat Attribution using Opinion Pools
Koen T. W. Teuwen
Cyber threat attribution can play an important role in increasing resilience against digital threats. Recent research focuses on automating the threat attribution process and on in…