用安全意图指导加密流量违规检测,提升准确性和可解释性。
INTACT: Intent-Aware Representation Learning for Cryptographic Traffic Violation Detection
- 将违规检测转化为基于行为和安全意图的条件约束学习
- 在真实数据上达到最高AUROC 1.0000,合成数据中更好识别复合违规
- 适合需要高可信度的加密通信监控场景
安全监控系统通常将异常检测视为对观测数据分布的统计偏离。但在加密流量分析中,违规并非由罕见性定义,而是由明确策略约束决定,包括禁止密钥复用、防止降级以及密钥生命周期受限。这种根本性差异限制了传统异常检测方法的可解释性和适应性。我们提出INTACT(INTent-Aware Cryptographic Traffic),一个策略条件化的框架,将违规检测重构为条件约束学习。不同于学习静态的行为特征决策边界,INTACT建模在观察行为和声明安全意图下违规的概率。该架构将表示学习分解为行为编码器和意图编码器,融合嵌入生成违规得分,产生策略参数化的决策边界族。我们在真实网络流数据集和包含21万条迹的合成多意图加密数据集上评估该框架。INTACT在真实数据上匹配或超越强基线,达到最高AUROC 1.0000;在合成设置中持续优于基线,有效检测关系型与复合型违规。结果表明,显式意图条件化显著提升了加密监控中的判别力、可解释性和鲁棒性。
原文摘要 · Abstract (English)
Security monitoring systems typically treat anomaly detection as identifying statistical deviations from observed data distributions. In cryptographic traffic analysis, however, violations are defined not by rarity but by explicit policy constraints, including key reuse prohibition, downgrade prevention, and bounded key lifetimes. This fundamental mismatch limits the interpretability and adaptability of conventional anomaly detection methods. We introduce INTACT (INTent-Aware Cryptographic Traffic), a policy-conditioned framework that reformulates violation detection as conditional constraint learning. Instead of learning a static decision boundary over behavioral features, INTACT models the probability of violation conditioned on both observed behavior and declared security intent. The architecture factorizes representation learning into behavioral and intent encoders whose fused embeddings produce a violation score, yielding a policy-parameterized family of decision boundaries. We evaluate the framework on a real-world network flow dataset and a 210,000-trace synthetic multi-intent cryptographic dataset. INTACT matches or exceeds strong unsupervised and supervised baselines, achieving near-perfect discrimination (AUROC up to 1.0000) in the real dataset and consistent superiority in detecting relational and composite violations in the synthetic setting. These results demonstrate that explicit intent conditioning improves discrimination, interpretability, and robustness in cryptographic monitoring.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。