arXiv:2605.27299cs.CRcs.AI2026-05

用模糊数建模三类不确定,让安全告警更智能排序

Risk Averse Alert Prioritization for IDS Using Subnormal Gaussian Fuzzy Models

论文配图:Risk Averse Alert Prioritization for IDS Using Subnormal Gaussian Fuzzy Models
图 1 · 摘自论文原文
  • 用不完全高斯模糊数表示告警,融合严重性、置信度和风险态度
  • 在CIC-IDS2017和NSL-KDD上比基线提升0.9963对0.8215的排序效果
  • 可调节风险偏好,适合需要动态调优安全策略的团队

现代入侵检测系统每日产生数千条告警,但因误报过多或影响低而引发告警疲劳,严重影响安全运营效率。本文提出一种基于不完全高斯模糊数的告警优先级排序框架,显式建模威胁严重性、检测置信度与组织风险态度三类不确定性。每条告警以模糊数表示,核心代表严重性,宽度反映不确定性,高度体现检测可靠性。通过排序指标对告警排序,允许组织通过风险态度参数调节安全策略。在CIC-IDS2017和NSL-KDD数据集上的实验表明,在检测器退化情况下,本方法的NDCGrel@100达到0.9963,显著优于基线的0.8215;在检测器表现良好时,与基线接近,且能有效区分中等置信度告警。该框架理论扎实、计算高效、推理可解释,并在不同检测器类型与校准偏差场景下保持鲁棒性。

原文摘要 · Abstract (English)

Modern intrusion detection systems generate thousands of alerts daily, but alert fatigue severely limits security operations effectiveness due to too many false positives or low-impact events. We address this by proposing a principled framework for alert prioritization based on subnormal Gaussian fuzzy numbers, explicitly modeling three sources of uncertainty: threat severity, detection confidence, and organizational risk attitude. Each alert is represented as a fuzzy number with the core indicating severity, spread indicating uncertainty, and height reflecting detection reliability. We apply ranking indices to prioritize alerts, allowing organizations to tune security posture through a risk-attitude parameter. Experimental validation on CIC-IDS2017 and NSL-KDD demonstrates greater robustness than baselines under detector degradation (0.9963 vs 0.8215 NDCGrel@100), with distinct differentiation in mid-confidence alerts and near-parity with baselines under robust detectors. The framework is theoretically grounded, computationally efficient, provides interpretable reasoning, and remains robust across detector families and miscalibration scenarios.

安全告警模糊逻辑风险建模

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。