ANR PLACID (in french)
Probabilistic graphical models and description logics for alarm correlation in intrusion detection.
This project is in the context of intrusion detection. It consists in providing probes with the ability to describe the observed events and to be able to reason about the alerts (correlation), while taking into account the elements of uncertainty. In particular, the project has studied new formal models of alert correlation based on the formalism of Bayesian networks and preference logics.