Risto Vaarandi

dblp:63/421 · DBLP profile ↗
← Back
10ranked-venue papers
7as first author
5since 2021 · last 2026
0000-0001-7781-5863ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Design and exploratory evaluation of a digital tabletop exercise for maritime cybersecurity
Muhammed Erbas, Sandesh K. Kafle, Daniel Volf, Jan Vykopal, Leonidas Tsiopoulos, Risto Vaarandi, Ricardo Lugo
Comput. Secur.6
2025 Evaluating Explainable AI for Deep Learning-Based Network Intrusion Detection System Alert Classification
abstract
A Network Intrusion Detection System (NIDS) monitors networks for cyber attacks and other unwanted activities. However, NIDS solutions often generate an overwhelming number of alerts daily, making it challenging for analysts to prioritize high-priority threats. While deep learning models promise to automate the prioritization of NIDS alerts, the lack of transparency in these models can undermine trust in their decision-making. This study highlights the critical need for explainable artificial intelligence (XAI) in NIDS alert classification to improve trust and interpretability. We employed a real-world NIDS alert dataset from Security Operations Center (SOC) of TalTech (Tallinn University Of Technology) in Estonia, developing a Long Short-Term Memory (LSTM) model to prioritize alerts. To explain the LSTM model's alert prioritization decisions, we implemented and compared four XAI methods: Local Interpretable Model-Agnostic Explanations (LIME), SHapley Additive exPlanations (SHAP), Integrated Gradients, and DeepLIFT. The quality of these XAI methods was assessed using a comprehensive framework that evaluated faithfulness, complexity, robustness, and reliability. Our results demonstrate that DeepLIFT consistently outperformed the other XAI methods, providing explanations with high faithfulness, low complexity, robust performance, and strong reliability. In collaboration with SOC analysts, we identified key features essential for effective alert classification. The strong alignment between these analyst-identified features and those obtained by the XAI methods validates their effectiveness and enhances the practical applicability of our approach.
Rajesh Kalakoti, Risto Vaarandi, Hayretdin Bahsi, Sven Nomm
ICISSP (1)2
2024 Hacking on the High Seas: How Automated Reverse-Engineering Can Assist Vulnerability Discovery of a Proprietary Communication Protocol
abstract
The digitalisation of the world is a global trend affecting many industries, including the maritime transport sector. Electronic navigational equipment aboard modern ships has undoubtedly decreased naval accidents, but these devices may suffer from cybersecurity vulnerabilities. One such vector, is its reliance on a great number of protocols for communication. Currently there is limited awareness of the security strengths and weaknesses of maritime protocols, because of the manual-reverse-engineering cost due to their proprietary nature. However, we substantiate that advances in automated protocol reverse-engineering are effectively lowering this cost. Our paper analyses a proprietary protocol, widely used in naval equipment. This protocol was reverse engineered through manual and automated techniques, revealing the advantages and drawbacks of both. Our results show that statistical automated protocol reverse-engineering techniques were sufficient to discover the relevant protocol fields. We introduce the disclosed communication structure and its vulnerabilities, which are both verified by the success of rudimentary attacks. The disclosed protocol, by manual and automated techniques, could also aid intrusion detection (and prevention) system development for maritime operational technology systems, to help vendors avoid the identified vulnerabilities during system design and implementation.
Gábor Visky, Alexander Rohl, Risto Vaarandi, Sokratis K. Katsikas, Olaf Maennel
LCN3
2024 Stream clustering guided supervised learning for classifying NIDS alerts
Risto Vaarandi, Alejandro Guerra-Manzanares
Future Gener. Comput. Syst.1
2024 Network IDS alert classification with active learning techniques
Risto Vaarandi, Alejandro Guerra-Manzanares
J. Inf. Secur. Appl.1
2018 An unsupervised framework for detecting anomalous messages from syslog log files
abstract
System logs provide valuable information about the health status of IT systems and computer networks. Therefore, log file monitoring has been identified as an important system and network management technique. While many solutions have been developed for monitoring known log messages, the detection of previously unknown error conditions has remained a difficult problem. In this paper, we present a novel data mining based framework for detecting anomalous log messages from syslog- based system log files. We also describe the implementation and performance of the framework in a large organizational network.
Risto Vaarandi, Bernhards Blumbergs, Markus Kont
NOMS1
2015 LogCluster - A data clustering and pattern mining algorithm for event logs
abstract
Modern IT systems often produce large volumes of event logs, and event pattern discovery is an important log management task. For this purpose, data mining methods have been suggested in many previous works. In this paper, we present the LogCluster algorithm which implements data clustering and line pattern mining for textual event logs. The paper also describes an open source implementation of LogCluster.
Risto Vaarandi, Mauno Pihelgas
CNSM1
2010 Network IDS alert classification with frequent itemset mining and data clustering
abstract
Network IDS is a well-known security measure for network monitoring and protection. Unfortunately, IDSs are known to generate large amounts of alerts, with many of them being either false positives or of low importance. This makes it hard for the human to spot alerts which need more attention. In order to tackle this issue, this paper proposes an IDS alert classification method which is based on data mining techniques.
Risto Vaarandi, Karlis Podins
CNSM1
2008 Mining event logs with SLCT and LogHound
abstract
With the growth of communication networks, event logs are increasing in size at a fast rate. Today, it is not uncommon to have systems that generate tens of gigabytes of log data per day. Log data are likely to contain information that deserves closer attention - such as security events - but the task of reviewing logs manually is beyond the capabilities of a human. This paper discusses data mining tools SLCT and log hound that were designed for assisting system management personnel in extracting knowledge from event logs.
Risto Vaarandi
NOMS1
2002 Platform independent event correlation tool for network management
abstract
Event correlation plays an important role in today's network management, reducing large amounts of network events to smaller and more meaningful sets of alarms. Most of the commercially available event correlation tools have a design that is over-complicated for majority of small and medium range applications, all of them are platform dependent, and last but not least, they are expensive for academic use. This paper presents a lightweight open source network management tool called sec designed to implement platform independent event correlation.
Risto Vaarandi
NOMS1