arXiv:2412.03442cs.LGcs.CR2024-12被引 1

用状态访问频次动态调整异常评分,提升网络流量异常检测效果

State Frequency Estimation for Anomaly Detection

  • 基于状态机状态访问频次动态计算异常分数
  • 在三个公开数据集上优于现有无监督方法
  • 可生成异常根因,便于告警分组与分析

许多研究探讨了状态机在检测网络流异常中的有效性。传统方法通常从无标签数据中学习模型,并根据轨迹出现的可能性或拟合度计算异常分数。然而,这些方法无法根据测试时观察到的轨迹动态调整分数。当攻击者生成看似常见的轨迹时,模型可能漏检,导致异常分数偏低。本文提出 SEQUENT,一种新的无监督方法,利用状态机的状态访问频次动态调整异常评分,实现更灵敏的检测。随后,该方法基于分数生成异常根因,有助于告警分组与异常分析。我们在三个公开的 NetFlow 数据集上评估了 SEQUENT 的有效性,并与多种现有无监督异常检测方法进行对比。结果表明,利用状态访问频次检测网络异常具有显著优势。

原文摘要 · Abstract (English)

Many works have studied the efficacy of state machines for detecting anomalies within NetFlows. These works typically learn a model from unlabeled data and compute anomaly scores for arbitrary traces based on their likelihood of occurrence or how well they fit within the model. However, these methods do not dynamically adapt their scores based on the traces seen at test time. This becomes a problem when an adversary produces seemingly common traces in their attack, causing the model to miss the detection by assigning low anomaly scores. We propose SEQUENT, a new unsupervised approach that uses the state visit frequency of a state machine to adapt its scoring dynamically for anomaly detection. SEQUENT subsequently uses the scores to generate root causes for anomalies. These allow the grouping of alarms and simplify the analysis of anomalies. We evaluate SEQUENT's effectiveness in detecting network anomalies on three publicly available NetFlow datasets and compare its performance against various existing unsupervised anomaly detection methods. Our evaluation shows promising results for using the state visit frequency of a state machine to detect network anomalies.

异常检测状态机网络流量无监督

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。