RUS  ENG
Full version
JOURNALS // Artificial Intelligence and Decision Making // Archive

Artificial Intelligence and Decision Making, 2023 Issue 2, Pages 3–14 (Mi iipr22)

Knowledge representation

Methods of intelligent system event analysis for multistep cyber-attack detection: using knowledge bases

I. V. Kotenko, D. A. Levshun

St. Petersburg Federal Research Center of the Russian Academy of Sciences

Abstract: This study presents a classification and comparative analysis of intelligent system event analysis methods for the detection of multistep cyber-attacks, which are a set of sequential actions of one or more attackers pursuing a specific goal of invasion. The paper studies approaches to multistep cyber-attack detection based on knowledge, such as expert rules and scenarios (sequences) of events. The approaches considered are analyzed according to the following criteria: the method for extracting knowledge about scenarios of system events and attacks, the method for scenario knowledge representation, the method for security events analysis and the security problem to be solved. The paper gives the main advantages and disadvantages of approaches to the multistep cyber-attack detection, as well as possible directions of research in this area.

Keywords: intelligent systems, knowledge bases, cybersecurity, multistep attack, security events, incident management.

DOI: 10.14357/20718594230201



Bibliographic databases:


© Steklov Math. Inst. of RAS, 2026