arXiv:2603.23459cs.CRcs.LG2026-03被引 1

构建统一安全数据底座,让AI更高效地检测网络攻击

CSTS: A Canonical Security Telemetry Substrate for AI-Native Cyber Detection

  • 设计通用安全遥测框架,整合多源异构数据
  • 支持异常检测、图学习等多元智能分析任务
  • 适配公有云/私有部署,降低数据工程成本

网络安全数据分散在不同厂商、格式和部署环境之间,导致人工智能与分析系统需耗费大量精力进行数据接入、标准化和依赖特定源的工程开发。本文提出标准安全遥测底座(CSTS),一种面向AI的通用遥测基础架构,可将异构网络安全数据统一为基于持久实体、类型关系、事件、时间状态与来源追溯的共同表示形式。CSTS遵循明确的设计原则,定义了核心表征组件,通过显式映射与可扩展元数据保留原始数据的细微差异,同时支持跨平台推理。该框架具备云无关与部署无关特性,适用于本地、混合及多云环境。最终形成统一的遥测模型,减轻网络安全数据工程的重复劳动,为可扩展、可互操作、模型无关的智能网络安全分析铺平道路。

原文摘要 · Abstract (English)

Cybersecurity data remains fragmented across vendors, formats, schemas, and deployment environments, forcing AI and analytics programs to spend disproportionate effort on ingestion, normalization, and brittle source-specific engineering. This paper introduces the Canonical Security Telemetry Substrate (CSTS), a canonical, AI-ready telemetry foundation designed to harmonize heterogeneous cyber data into a common representation over persistent entities, typed relations, events, temporal state, and provenance. CSTS is intended to move cybersecurity analytics beyond ad hoc record normalization toward a reusable substrate that supports anomaly detection, graph learning, forecasting, behavior-based modeling, and agentic cyber AI. We formalize the core design principles of CSTS, define its representational components, and explain how it preserves source-specific nuance through explicit mappings and extensible metadata while still enabling portable downstream inference. We further position CSTS as a cloud-agnostic and deployment-agnostic substrate suitable for on-prem, hybrid, and multi-cloud environments. The result is a unifying telemetry model that reduces the blue-collar burden of cyber data engineering and creates a clearer path to scalable, interoperable, and model-agnostic cyber AI.

安全检测数据融合AI底座遥测框架

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。