Abstract
Event log correlation (ELC) is central to detecting multi-step attacks (MSAD) that unfold across heterogeneous systems and long time horizons. This review synthesises ELC families—mining/sequence, graph learning, provenance/causal correlation, and hybrid LLM-assisted approaches—through an MSAD-first lens that ties methods to attack stages and datasets. We report operational metrics (false-alarm reduction, detection time, throughput/storage) and classifier metrics (Accuracy/F1) as the authors present them, enabling fair comparison across 2025 works. Compared with prior surveys, we contribute a challenge mitigation map (false positives, latency/throughput, heterogeneity), a 2025-only section covering NDSS/USENIX/Neurocomputing studies and a recent Graph Convolutional Network (GCN) article (Multi dataset, Multi-family detection pipeline), and a roadmap spanning mining, graph, provenance/causal, and LLM-assisted correlation for scalable, real-time deployments. We also provide an attack-coverage matrix and a machine-readable extraction (8 papers 15+ fields) to support reproducible synthesis and practitioner adoption.
| Original language | English |
|---|---|
| Article number | e70151 |
| Number of pages | 19 |
| Journal | SECURITY AND PRIVACY |
| Volume | 9 |
| Issue number | 1 |
| Early online date | 30 Nov 2025 |
| DOIs | |
| Publication status | Published - 1 Jan 2026 |
Fingerprint
Dive into the research topics of 'Event Log Correlation for Multi‐Step Attack Detection'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver