用不确定性感知模型识别网络攻击阶段,提升安全响应准确性。
Preliminary Investigation into Uncertainty-Aware Attack Stage Classification
- 基于证据深度学习输出攻击阶段的置信度分布。
- 在模拟环境中准确推断攻击阶段并检测异常输入。
- 适合需要动态防御的网络安全系统部署。
高级持续性威胁(APTs)因其长期、多阶段特性及攻击者的技术复杂性,成为网络安全的重大挑战。传统检测系统通常以二元方式判断行为是否恶意,却忽略了攻击进展阶段。有效的应对策略依赖于对当前攻击阶段的准确推断,因为防御措施需针对侦察、利用或数据窃取等不同阶段进行适配。本文研究在不确定性下的攻击阶段分类问题,重点关注对分布外(OOD)输入的鲁棒性。提出一种基于证据深度学习(EDL)的分类方法,通过输出狄利克雷分布参数来建模预测不确定性,不仅能给出最可能的攻击阶段,还能标识出不确定或超出训练分布的输入。初步实验在模拟环境中表明,该模型可实现校准的置信度,准确推断攻击阶段,并有效检测分布外输入,可能反映攻击者战术变化。结果支持在动态对抗环境中部署不确定性感知模型进行分阶段威胁检测的可行性。
原文摘要 · Abstract (English)
Advanced Persistent Threats (APTs) represent a significant challenge in cybersecurity due to their prolonged, multi-stage nature and the sophistication of their operators. Traditional detection systems typically focus on identifying malicious activity in binary terms (benign or malicious) without accounting for the progression of an attack. However, effective response strategies depend on accurate inference of the attack's current stage, as countermeasures must be tailored to whether an adversary is in the early reconnaissance phase or actively conducting exploitation or exfiltration. This work addresses the problem of attack stage inference under uncertainty, with a focus on robustness to out-of-distribution (OOD) inputs. We propose a classification approach based on Evidential Deep Learning (EDL), which models predictive uncertainty by outputting parameters of a Dirichlet distribution over possible stages. This allows the system not only to predict the most likely stage of an attack but also to indicate when it is uncertain or the input lies outside the training distribution. Preliminary experiments in a simulated environment demonstrate that the proposed model can accurately infer the stage of an attack with calibrated confidence while effectively detecting OOD inputs, which may indicate changes in the attackers' tactics. These results support the feasibility of deploying uncertainty-aware models for staged threat detection in dynamic and adversarial environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。