用分层置信预测提升操作系统指纹识别的可靠性与结构一致性
Reliable Hierarchical Operating System Fingerprinting via Conformal Prediction
- 设计两种分层置信预测策略,利用系统层级结构增强指纹识别
- 分层策略在不同场景下实现精度与一致性的权衡:人审选紧集,机控选稳集
- 首次将置信预测引入操作系统指纹领域,兼顾可解释性与自动化部署
操作系统指纹识别对网络安全至关重要,但传统方法缺乏形式化的不确定性量化机制。置信预测(CP)可直接嵌入现有方法以生成具有保证覆盖率的预测集。然而,直接应用会将操作系统识别视为扁平分类问题,忽略其天然的分类层级结构,导致预测结果脆弱。本文提出并评估了两种不同的结构化置信预测策略:逐级置信预测(L-CP),独立校准每一层级;基于投影的置信预测(P-CP),通过向上投影确保叶节点预测集的结构一致性。实验表明,两者均满足有效性保证,但在层级效率与结构一致性间存在根本权衡:L-CP产生更紧凑的预测集,适合人工取证分析,但存在分类不一致问题;而P-CP能生成层次一致、嵌套的预测集,适用于自动化策略执行,但在粗粒度层级上效率较低。
原文摘要 · Abstract (English)
Operating System (OS) fingerprinting is critical for network security, but conventional methods do not provide formal uncertainty quantification mechanisms. Conformal Prediction (CP) could be directly wrapped around existing methods to obtain prediction sets with guaranteed coverage. However, a direct application of CP would treat OS identification as a flat classification problem, ignoring the natural taxonomic structure of OSs and providing brittle point predictions. This work addresses these limitations by introducing and evaluating two distinct structured CP strategies: level-wise CP (L-CP), which calibrates each hierarchy level independently, and projection-based CP (P-CP), which ensures structural consistency by projecting leaf-level sets upwards. Our results demonstrate that, while both methods satisfy validity guarantees, they expose a fundamental trade-off between level-wise efficiency and structural consistency. L-CP yields tighter prediction sets suitable for human forensic analysis but suffers from taxonomic inconsistencies. Conversely, P-CP guarantees hierarchically consistent, nested sets ideal for automated policy enforcement, albeit at the cost of reduced efficiency at coarser levels.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。