Andrea Burattin

Associate Professor
Technical University of Denmark


From Behavior to Breach: Modeling, Simulating and Detecting Attacks with Process Mining

L. D'Este , E.L. Mortensen, E.P. Rasmussen, C.E. Budde, N. Dragoni, and A. Burattin
Abstract

As digital systems expand in scope and complexity, the sophistication and frequency of cyber attacks increase as well. Digital systems keep track of all relevant events in system logs, which can be used for further analysis. This paper investigates the use of process mining on system logs to identify whether cyber attacks can be found and, if this is the case, which attacks have happened (either known or unknown ones, i.e., zero-day). To accomplish this goal we propose to formally model benign and attack behaviors and use process mining and conformance checking for detection. Additionally, having formal models allows to generate synthetic data referring to both benign behavior and attacks. The paper demonstrates the viability of the presented techniques using a real-world case study that analyzes Windows Security Logs to identify cyber attacks, modeled from the MITRE ATT&CK framework.

The contribution of this paper comprises: the modeling of benign behavior and cyber attacks in a formal way, the generation of conformant attack logs, the conformance-based attacks detection, and a real-world case study where all the contributions are validated. All data, models, and code are available online.

Paper Information and Files

In Proceedings of EDOC, 2026 (to appear).

General rights

Copyright and moral rights for the publications made accessible in the public website are retained by the authors and/or other copyright owners and it is a condition of accessing publications that users recognise and abide by the legal requirements associated with these rights.

If you believe that this document breaches copyright please contact us providing details, and we will remove access to the work immediately and investigate your claim.

Latest website update: 21 September 2026.