用AI融合日志与恶意软件检测,提升云安全中心的威胁识别能力
Cloud Security Leveraging AI: A Fusion-Based AISOC for Malware and Log Behaviour Detection
- 融合云端日志与恶意软件检测结果,实现多模态威胁分析
- 在受控环境下融合模型宏F1达1.00,有效识别三类威胁等级
- 适合预算有限、需快速部署的云安全团队使用
云安全运营中心(Cloud SOC)通过提供可见性与控制力,支持云治理、风险与合规。面对弹性、短生命周期资源产生的海量异构数据,且需在严格预算内运行,本研究在AWS上构建了基于AI的安全部署中心(AISOC),结合云原生监控与机器学习检测。系统采用三个Amazon EC2实例:攻击者、防御者与监控端。使用Metasploit模拟反向壳攻击,Filebeat将防御者日志推送至Elasticsearch与Kibana堆栈进行分析。训练两个分类器:基于公开数据集的恶意软件检测器,以及基于合成增强日志(含对抗样本)的异常日志检测器。对得分进行校准并融合,生成多模态威胁情报,将活动分类为NORMAL、SUSPICIOUS和HIGH_CONFIDENCE_ATTACK。在保留测试中,融合模型在受控条件下达到最高宏F1为1.00,但实际噪声更大、多样性更高的环境中性能会下降。结果表明,在资源受限、成本敏感的场景下,简单的校准融合可显著增强云SOC能力。
原文摘要 · Abstract (English)
Cloud Security Operations Center (SOC) enable cloud governance, risk and compliance by providing insights visibility and control. Cloud SOC triages high-volume, heterogeneous telemetry from elastic, short-lived resources while staying within tight budgets. In this research, we implement an AI-Augmented Security Operations Center (AISOC) on AWS that combines cloud-native instrumentation with ML-based detection. The architecture uses three Amazon EC2 instances: Attacker, Defender, and Monitoring. We simulate a reverse-shell intrusion with Metasploit, and Filebeat forwards Defender logs to an Elasticsearch and Kibana stack for analysis. We train two classifiers, a malware detector built on a public dataset and a log-anomaly detector trained on synthetically augmented logs that include adversarial variants. We calibrate and fuse the scores to produce multi-modal threat intelligence and triage activity into NORMAL, SUSPICIOUS, and HIGH\_CONFIDENCE\_ATTACK. On held-out tests the fusion achieves strong macro-F1 (up to 1.00) under controlled conditions, though performance will vary in noisier and more diverse environments. These results indicate that simple, calibrated fusion can enhance cloud SOC capabilities in constrained, cost-sensitive setups.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。