RUS  ENG
Full version
JOURNALS // Artificial Intelligence and Decision Making // Archive

Artificial Intelligence and Decision Making, 2023 Issue 3, Pages 3–15 (Mi iipr32)

This article is cited in 1 paper

Knowledge representation

Methods of intelligent system event analysis for multistep cyber-attack detection: using machine learning methods

I. V. Kotenko, D. A. Levshun

St. Petersburg Federal Research Center of the Russian Academy of Sciences, St. Petersburg, Russia

Abstract: This study presents a classification and comparative analysis of intelligent system event methods for the detection of multi-step cyber-attacks. Such attacks are a sequence of interrelated steps of an attacker pursuing a specific goal of intrusion. The paper analyzes approaches to multistep cyber-attack detection based on system event learning methods, including supervised learning, unsupervised learning, and semi-supervised learning. The approaches considered are analyzed according to the following criteria: the method of extracting knowledge about scenarios of system events and attacks, the method for scenario knowledge representation, the method for security events analysis, the security problem to be solved, and the data set used. The paper gives the main advantages and disadvantages of learningbased approaches to the detection of multi-step cyberattacks, as well as possible directions of research in this area.

Keywords: intelligent systems, knowledge bases, cybersecurity, multistep attack, security events, incident management.

DOI: 10.14357/20718594230301



Bibliographic databases:


© Steklov Math. Inst. of RAS, 2026