用知识图谱+大模型+不平衡学习提升网络威胁检测准确率与可解释性。
Improving Network Threat Detection by Knowledge Graph, Large Language Model, and Imbalanced Learning
- 构建知识图谱分析用户行为模式,结合不平衡学习优化图结构。
- 在真实数据上实现威胁捕获率提升3%-4%,风险预测更可解释。
- 适合安全分析、AI驱动的威胁检测研究者使用。
由于攻击行为复杂且历史威胁数据有限,网络威胁检测面临挑战。为改进现有基于分析、机器学习和人工智能的检测方法,本文提出一种集成建模框架:利用知识图谱分析用户行为模式,通过不平衡学习技术对知识图谱进行剪枝与加权,并借助大语言模型从知识图谱中检索并解释用户活动。该框架应用于在线顺序学习下的敏捷威胁检测,初步结果表明,威胁捕获率提升3%-4%,风险预测的可解释性显著增强。
原文摘要 · Abstract (English)
Network threat detection has been challenging due to the complexities of attack activities and the limitation of historical threat data to learn from. To help enhance the existing practices of using analytics, machine learning, and artificial intelligence methods to detect the network threats, we propose an integrated modelling framework, where Knowledge Graph is used to analyze the users' activity patterns, Imbalanced Learning techniques are used to prune and weigh Knowledge Graph, and LLM is used to retrieve and interpret the users' activities from Knowledge Graph. The proposed framework is applied to Agile Threat Detection through Online Sequential Learning. The preliminary results show the improved threat capture rate by 3%-4% and the increased interpretabilities of risk predictions based on the users' activities.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。