用自监督模型提升复杂网络中警报分组准确性
AlertBERT: A noise-robust alert grouping framework for simultaneous cyber attacks
- 基于掩码语言模型与密度聚类的自监督框架
- 在高噪声环境下准确识别并发攻击警报组
- 适合安全运营中心应对警报疲劳问题
自动化检测网络攻击对应对日益增长且复杂的攻击至关重要。然而,入侵检测系统产生的大量安全警报导致安全运营中心(SOC)分析师出现警报疲劳,进而造成响应延迟和误判。警报分组(按根本原因聚类警报)可显著减少分析师需处理的独立项数。传统基于时间的分组方法不适用于大规模网络中存在大量误报和并发攻击的情况。为此,我们提出 AlertBERT,一种自监督框架,可在噪声环境中对孤立或同时发生的攻击警报进行分组。该开源实现利用掩码语言模型与密度聚类,支持实时或事后分析。为评估框架,我们引入一种新颖的数据增强方法,可灵活控制噪声水平并模拟并发攻击。基于生成数据集的实验表明,AlertBERT 在识别正确警报组方面始终优于传统时间分组技术。
原文摘要 · Abstract (English)
Automated detection of cyber attacks is a critical capability to counteract the growing volume and sophistication of cyber attacks. However, the high numbers of security alerts issued by intrusion detection systems lead to alert fatigue among analysts working in security operations centres (SOC), which in turn causes slow reaction time and incorrect decision making. Alert grouping, which refers to clustering of security alerts according to their underlying causes, can significantly reduce the number of distinct items analysts have to consider. Unfortunately, conventional time-based alert grouping solutions are unsuitable for large scale computer networks characterised by high levels of false positive alerts and simultaneously occurring attacks. To address these limitations, we propose AlertBERT, a self-supervised framework designed to group alerts from isolated or concurrent attacks in noisy environments. Thereby, our open-source implementation of AlertBERT leverages masked-language-models and density-based clustering to support both real-time or forensic operation. To evaluate our framework, we further introduce a novel data augmentation method that enables flexible control over noise levels and simulates concurrent attack occurrences. Based on the data sets generated through this method, we demonstrate that AlertBERT consistently outperforms conventional time-based grouping techniques, achieving superior accuracy in identifying correct alert groups.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。