融合结构与隐空间信息,提升网络异常检测准确率
Hybrid Latent-Structural Fusion (HLSF) for Cyber Anomaly Detection

- 结合CP-APR结构得分与流模型隐空间密度得分
- 在LANL真实数据上优于单一方法
- 适合需要高精度异常检测的网络安全场景
恶意异常活动检测是网络安全系统的核心挑战。基于统计框架的张量分解方法(如交替泊松回归的CP-APR)和归一化流(normalizing flows)已被证明是强大的无监督机器学习工具,能够建模多维数据并捕捉行为特征的复杂细节。本文提出混合潜在-结构融合(HLSF)框架,通过加权融合CP-APR的结构异常得分与归一化流生成的隐空间密度得分。实验基于洛斯阿拉莫斯国家实验室(LANL)大型企业网络在红队演练中收集的真实用户凭证数据集,结果表明,HLSF在异常检测性能上优于单独使用CP-APR或归一化流。
原文摘要 · Abstract (English)
Malicious anomalous activity detection is a fundamental challenge for cyber security systems. Both tensor decomposition under statistical framework with CANDECOMP-PARAFAC alternating Poisson regression (CP-APR) and normalizing flows have proven to be powerful unsupervised machine learning methods that model multi-dimensional data and capture complex and multi-faceted details of behavior profiles in cyber security applications. In this study, we propose Hybrid Latent-Structural Fusion (HLSF), a weighted anomaly fusion framework integrating CP-APR structural anomaly scores with latent-space density scores derived from normalizing flows. In our experiments, we show that the HLSF framework improves anomaly detection performance on a dataset of real-world compromised user credentials collected from the large enterprise network of Los Alamos National Laboratory (LANL) during a red-teaming exercise, compared with using CP-APR or normalizing flows alone.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。