调整安全规则可缓解数据不平衡,提升自动化告警分类的准确性和可解释性。
On the Effect of Ruleset Tuning and Data Imbalance on Explainable Network Security Alert Classifications: a Case-Study on DeepCASE
- 通过优化SOC检测规则减少标签不平衡问题
- 不平衡数据会降低DeepCASE分类性能与解释可信度
- 适合关注安全自动化可解释性的研究人员和工程师
安全运营中心(SOC)中的自动化在告警分类与事件升级中起关键作用。然而,自动化方法在输入数据不平衡时表现易受影响,且需提供可解释决策。本文以最先进的告警分类方法DeepCASE为案例,评估标签不平衡对网络入侵告警分类的影响。结果表明,不平衡数据会同时降低分类性能与DeepCASE提供的解释正确性。研究发现,调整SOC中使用的检测规则可显著减少数据不平衡,从而提升如DeepCASE等后处理方法的性能与可解释性。因此,传统数据质量优化手段有助于自动化系统的改进。
原文摘要 · Abstract (English)
Automation in Security Operations Centers (SOCs) plays a prominent role in alert classification and incident escalation. However, automated methods must be robust in the presence of imbalanced input data, which can negatively affect performance. Additionally, automated methods should make explainable decisions. In this work, we evaluate the effect of label imbalance on the classification of network intrusion alerts. As our use-case we employ DeepCASE, the state-of-the-art method for automated alert classification. We show that label imbalance impacts both classification performance and correctness of the classification explanations offered by DeepCASE. We conclude tuning the detection rules used in SOCs can significantly reduce imbalance and may benefit the performance and explainability offered by alert post-processing methods such as DeepCASE. Therefore, our findings suggest that traditional methods to improve the quality of input data can benefit automation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。