Register
Register
Register

ProfileUpdated on 14 October 2024

Cyber defence using automatic event correlation for detecting abnormalities

Michael W. Mürling

Marketing and Communications Manager at AIT Austrian Institute of Technology

About

Experts at the research and technology organisation AIT Austrian Institute of Technology are working on leading-edge technologies and solutions based on novel machine-learning concepts for future cyber defence ecosystems. The aim is to tackle cyber threats within comprehensive information and communication technology networks, which result from their increasing interconnectedness and unclear attack surfaces.

The tool AECID stands for Automatic Event Correlation for Incident Detection and is an intelligent cybersecurity tool that uses special mathematical calculations to distinguish abnormalities from normal behaviour in complex computer networks. It is applied in the field of blockchain technologies to provide insight into functionality and transaction flows for the real-time analysis of virtual currency transactions. A particular focus lies in the detection of "anomalies“ , i.e., the identification of transactions and transaction patterns that deviate from the usual structures. The patented solution AECID builds upon system behaviour models to understand relevant events and how they are interrelated. It is created as a self-learning solution for adaptive networks. Log stream processing can help to detect, classify and cluster frequently occurring patterns in log files and events and to eventually distinguish good from unknown malicious activities in the IT infrastructures of enterprises.

  • In contrast to conventional systems, the algorithm does not need specific knowledge about the IT systems to be monitored. Instead, a self-learning algorithm conducts pure pattern recognition after appropriate observation and study time.
  • AIT ´s AECID technology continuously adapts to new situations and does not require an elaborate specification of the technical system and or a complex "configuration management" by the operator.
  • By constantly gathering and analysing new information, AECID independently and continuously enhances and refines its own knowledge base for new insights into the system in which it is used.

Language Tag

  • English

Security

  • Cyber

Product Info

https://www.ait.ac.at/en/research-fields/cyber-security/our-offer/aecid/

Organisation

Similar opportunities