Faglige nøgleord: Process mining, behavior monitor, attack detection, anomaly detection, cybersecurity
Oplæg tilgængeligt på: Engelsk og italiensk
Current solutions to detect cyberattacks are not able to understand why something is a problem, and so create many false alerts. By using process mining, which is used to improve business processes in businesses, healthcare, finance ... we can understand what's happening and why something can be an attack. What we do is that we model the normal behavior of a system, and with some known attacks, and then we compare logs of what's happening to these models and can do detection
The research is relevant because it could help reduce the amount of successful cyberattacks.
I'm from Italy, in high school I studied mechanics/mechatronics as a half technical school, in bachelor university I studied information engineering, in the master I moved here and studied AI and now I'm doing this PhD on process mining into cybersecurity