Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills
  1. Outputs

Classifying traces of event logs on the basis of security risks

Conference Paper
Publication Date:
2015
abstract:
We address the problem of classifying log traces in the context of security risk analysis concerning business processes. Specifically, on the basis of some (possibly incomplete) knowledge of the structures of the processes and of the patterns representing undesired/risky behaviors, we aim at classifying each log trace as instance of some process and/or as potential security breach. In particular, we address the following challenging setting: each event has not a unique interpretation in terms of the activity of which it is a step, but it can correspond to more than one activity. In our framework, the mapping between events and activities is encoded by probability distributions over events and activities, and both the models describing the processes and the security breaches are expressed in terms of precedence/causality rules over the activities. Each trace is classified on the basis of the conformance of its possible interpretations, generated by a Monte Carlo mechanism, to the security-breach models and/or the to process models. The proposed framework has been experimentally validated, and proved to be efficient and effective.
Iris type:
04.01 Contributo in Atti di convegno
Keywords:
process mining; security
List of contributors:
Pontieri, Luigi; Fazzinga, Bettina
Authors of the University:
FAZZINGA BETTINA
PONTIERI LUIGI
Handle:
https://iris.cnr.it/handle/20.500.14243/306752
  • Use of cookies

Powered by VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)