AI 中文总结
针对网络遥测行为异常检测,提出有限维宏观状态框架,在CSTS上实例化,对相关元素粗粒度处理,建模宏观状态转换,经数据集评估,相比多种基线和检测器,提升异常判别能力及行为分析可解释性。
AI 中文摘要
基于熵的方法长期用于网络异常检测,但现有多数方法将熵视为狭义可观测量上的标量统计量,而非网络系统更广泛行为状态空间的一部分。我们为网络遥测提出了一个有限维宏观状态框架,在规范安全遥测基础(CSTS)上实例化,以便在持久实体、类型化关系和时间状态上进行粗粒度处理,而非孤立事件记录。由此产生的宏观状态捕获活动、分布无序、结构组织、时间波动性、持久性以及与良性基线的偏差。我们对窗口到窗口的宏观状态转换进行建模并定义状态结构、稳定性和异常变化,这有助于区分良性工作负载漂移和对抗性重组。我们在基准网络遥测数据集上评估该框架,并与香农、雷尼和蔡利斯风格的熵基线以及标准异常检测器进行比较。所提出的表示方法提高了异常判别能力,并支持对网络遥测进行更具可解释性的行为分析。
英文摘要
Entropy-based methods have long been used for network anomaly detection, but most existing approaches treat entropy as a scalar statistic on narrow observables rather than as part of a broader behavioral state-space for cyber systems. We propose a finite-dimensional macrostate framework for network telemetry, instantiated over the Canonical Security Telemetry Substrate (CSTS), so that coarse-graining is performed over persistent entities, typed relations, and temporal state rather than isolated event records. The resulting macrostate captures activity, distributional disorder, structural organization, temporal volatility, persistence, and deviation from benign baselines. Rather than scoring only unusual states, we model window-to-window macrostate transitions and define regime structure, stability, and anomalous change. This supports discrimination between benign workload drift and adversarial reorganization. We evaluate the framework on benchmark network telemetry datasets and compare it against Shannon-, Rényi-, and Tsallis-style entropy baselines, as well as standard anomaly detectors. The proposed representation improves anomaly discrimination and supports more interpretable behavioral analysis of cyber telemetry.