arXiv:2608.05605cs.CRcs.LG2026-08被引 1

用动态基线区分科研网络的正常流量与攻击,降低误报率。

Enhancing Anomaly Resilience in Research Networks: A Large-Scale Forecasting Benchmark for Dynamic Security Baselining

论文配图:Enhancing Anomaly Resilience in Research Networks: A Large-Scale Forecasting Benchmark for Dynamic Security Baselining
图 1 · 摘自论文原文
  • 基于57天真实数据构建动态预测框架,识别科学流量特征。
  • 先进模型(如TiDE)使预测误差降低30%-42%,显著提升区分能力。
  • 提出新抗噪策略,增强模型在干扰下的稳定性,适合网络安全研究者。

科研与教育网络(RENs)是科学发现的关键基础设施,但其正常流量常呈现大规模、突发性的“大象流”特征,与分布式拒绝服务(DDoS)等攻击在统计上难以区分,导致传统监测系统误报率高,掩盖真实威胁。本文提出并评估了一种高保真流量预测框架,用于建立动态安全基线。基于涵盖十台主干路由器、共137亿包的独家57天Internet2数据集,我们首次在该领域开展大规模基准测试,系统评估六类模型(从SARIMA到TiDE、PatchTST等长序列架构),覆盖960种配置。结果表明,先进架构(尤其是TiDE)相比传统方法将基线预测误差降低30%-42%(p < 0.001),显著提升对合法科学流量与潜在异常的区分能力。此外,引入新型异常融合策略,在噪声环境下使模型鲁棒性提升3.3%。本工作首次提供统计验证的框架,实现科学工作流与网络攻击的可靠区分,推动更自主、韧性的网络安全管理。

原文摘要 · Abstract (English)

Research and Education Networks (RENs) serve as critical infrastructure for scientific discovery, yet they face a unique security paradox: their normal traffic patterns which are characterized by massive, bursty "elephant flows" are statistically indistinguishable from volumetric attacks such as DDoS to conventional monitoring systems. This similarity leads to high false-positive rates in anomaly detection, blinding security operators to genuine threats. In this paper, we propose and evaluate a high-fidelity traffic forecasting framework designed to establish dynamic security baselines for RENs. Leveraging an exclusive 57-day Internet2 dataset spanning ten backbone routers (13.7 billion packets), we perform the first large-scale benchmark of anomaly-aware forecasting models in this domain. We systematically evaluate six model families, from SARIMA to state-of-the-art long-sequence architectures (TiDE, PatchTST), across 960 experimental configurations. Our results demonstrate that these advanced architectures, particularly TiDE, reduce baseline prediction error by 30-42% compared to traditional methods ($p < 0.001$), significantly improving the distinction between legitimate scientific bursts and potential anomalies. Furthermore, we introduce a novel anomaly-integration strategy that improves model robustness by 3.3% in the presence of noise. This work provides the first statistically validated framework for distinguishing scientific workflows from network attacks, enabling more autonomous and resilient network security operations.

网络安全流量预测异常检测科研网络

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。