用混合AI与规则检测分布式事件系统的安全威胁
SECUREVENT: Hybrid AI/ML Security Monitoring for Distributed Event-Based Systems
- 结合机器学习与传统安全机制,实时监控事件流行为
- 在模拟攻击中实现高召回率且误报率低
- 适合动态性强的云原生、物联网等系统安全防护
分布式事件驱动系统已成为互联网规模发布/订阅服务、物联网遥测、云原生微服务和安全运营流水线的常见基础架构。其松耦合和异步交付提升了可扩展性,但也扩大了攻击面:发布者、代理、订阅者、主题、模式和时间顺序均可能被滥用,而单一组件无法观察全局行为。本文提出 SECUREVENT,一种面向分布式事件系统的混合型AI/ML安全监控架构。该架构融合了认证传输、主题级授权、签名事件等传统防护手段,以及在线异常检测、图感知行为特征、复杂事件策略规则、联邦学习和对抗性机器学习治理。通过合成事件流攻击的确定性原型研究,表明混合式AI/CEP监控可在保持低误报率的同时提升召回率。核心观点并非以机器学习替代加密与访问控制,而是强调当事件流、身份、模式和时序关系过于动态时,基于模型的安全监控不可或缺。
原文摘要 · Abstract (English)
Distributed event-based systems have become a common substrate for Internet-scale publish/subscribe services, IoT telemetry, cloud-native microservices, and security operations pipelines. Their loose coupling and asynchronous delivery improve scalability, but they also expand the attack surface: publishers, brokers, subscribers, topics, schemas, and temporal ordering can each be abused without a single component observing the whole behavior. This paper proposes SECUREVENT, a hybrid AI/ML security-monitoring architecture for distributed event-based systems. The architecture combines traditional protections such as authenticated transport, topic-level authorization, and signed events with online anomaly detection, graph-aware behavioral features, complex-event policy rules, federated learning, and adversarial-ML governance. A deterministic prototype study over synthetic event-stream attacks illustrates how a hybrid AI/CEP monitor can improve recall over static rules while retaining a low false-positive rate. The central claim is not that machine learning replaces cryptographic and access-control mechanisms, but that model-based security monitoring is necessary when event flows, identities, schemas, and timing relationships are too dynamic for static controls alone.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。