arXiv:2510.02424cs.CRcs.LG2025-10被引 1

用行为分析动态骗术,99.88%检出率,误报仅0.13%

Adaptive Deception Framework with Behavioral Analysis for Enhanced Cybersecurity Defense

  • 融合机器学习与行为画像,动态调整欺骗策略
  • 在CICIDS2017上实现99.88%检出率,0.13%误报率
  • 开源可部署,比商用方案省150-400美元/主机/年

本文提出CADL(认知自适应欺骗层)框架,在CICIDS2017数据集上实现99.88%的检测率和0.13%的误报率。该框架结合随机森林、XGBoost、神经网络等集成机器学习方法与行为画像技术,识别并自适应响应网络入侵。通过协同信号总线架构,安全组件实时共享情报,实现集体决策。系统基于时间模式对攻击者建模,并在五个升级层级部署定制化欺骗策略。在5万条CICIDS2017测试样本上的评估表明,CADL显著优于传统入侵检测系统(Snort:71.2%,Suricata:68.5%),同时保持生产级低误报率。行为分析在攻击者画像分类中达到89%准确率。我们提供开源实现与透明性能指标,为年成本150-400美元/主机的商用欺骗平台提供低成本替代方案。

原文摘要 · Abstract (English)

This paper presents CADL (Cognitive-Adaptive Deception Layer), an adaptive deception framework achieving 99.88% detection rate with 0.13% false positive rate on the CICIDS2017 dataset. The framework employs ensemble machine learning (Random Forest, XGBoost, Neural Networks) combined with behavioral profiling to identify and adapt responses to network intrusions. Through a coordinated signal bus architecture, security components share real-time intelligence, enabling collective decision-making. The system profiles attackers based on temporal patterns and deploys customized deception strategies across five escalation levels. Evaluation on 50,000 CICIDS2017 test samples demonstrates that CADL significantly outperforms traditional intrusion detection systems (Snort: 71.2%, Suricata: 68.5%) while maintaining production-ready false positive rates. The framework's behavioral analysis achieves 89% accuracy in classifying attacker profiles. We provide open-source implementation and transparent performance metrics, offering an accessible alternative to commercial deception platforms costing $150-400 per host annually.

网络安全欺骗防御行为分析机器学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。