arXiv:2503.00871cs.LGcs.AI2025-03中稿 · WWW 2025 short res…被引 2

实时检测网络安全异常,识别多种入侵模式。

CyberCScope: Mining Skewed Tensor Streams and Online Anomaly Detection in Cybersecurity Systems

  • 将高阶张量分解为趋势成分,区分类别与偏态连续属性。
  • 在真实数据集上准确识别多种入侵,比现有方法提升性能。
  • 适合需要实时分析网络流数据的安全部门或系统管理员。

网络安全系统持续生成大量带时间戳的高阶张量事件,如{计数;时间、端口、流持续时间、包大小等},如何实现实时异常检测?如何识别多种入侵并捕捉其特征行为?张量数据包含类别和连续属性,且连续属性分布通常呈偏态。这要求同时处理偏态的无限与有限维空间。本文提出一种新型流式方法CyberCScope,能有效将输入张量分解为主流趋势,并明确区分类别属性与偏态连续属性。据我们所知,这是首个实现混合偏态无限与有限维分解的方法。基于该分解,可流式发现随时间演化的不同模式,从而检测多种异常。大规模真实数据集上的实验表明,CyberCScope在检测各类入侵时精度高于当前最优基线,同时提供实际入侵事件的有意义摘要。

原文摘要 · Abstract (English)

Cybersecurity systems are continuously producing a huge number of time-stamped events in the form of high-order tensors, such as {count; time, port, flow duration, packet size, . . . }, and so how can we detect anomalies/intrusions in real time? How can we identify multiple types of intrusions and capture their characteristic behaviors? The tensor data consists of categorical and continuous attributes and the data distributions of continuous attributes typically exhibit skew. These data properties require handling skewed infinite and finite dimensional spaces simultaneously. In this paper, we propose a novel streaming method, namely CyberCScope. The method effectively decomposes incoming tensors into major trends while explicitly distinguishing between categorical and skewed continuous attributes. To our knowledge, it is the first to compute hybrid skewed infinite and finite dimensional decomposition. Based on this decomposition, it streamingly finds distinct time-evolving patterns, enabling the detection of multiple types of anomalies. Extensive experiments on large-scale real datasets demonstrate that CyberCScope detects various intrusions with higher accuracy than state-of-the-art baselines while providing meaningful summaries for the intrusions that occur in practice.

异常检测流式计算网络安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。