arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

为安全分析师解释基于深度学习的网络入侵检测系统的入侵警报决策

Explaining Intrusion Alert Decisions of Deep Learning-based Network Intrusion Detection Systems for Security Analysts

Ayush Kumar, Vrizlynn L. L. Thing

arXiv 2607.12203首次发表:更新:

AI 中文总结

本文提出EXP-SEC框架,能为安全分析师解释基于深度学习的网络入侵检测系统的入侵警报决策。该框架含取证、解释和多阶段映射模块,评估显示其在组级和重叠感知解释效用指标上优于现有框架,还展示了对分析师友好的解释格式。

AI 中文摘要

在本文中,我们提出了EXP-SEC,这是一个新颖的框架,它能够以与安全运营中心(SOC)分析师的领域知识相一致的方式,解释基于深度学习的网络入侵检测系统(NIDS)导致安全警报的入侵检测决策。我们强调了我们框架的以下特点:一个取证模块,用于隔离可能导致警报的可疑数据包/流;一个解释模块,它能够处理网络流量中比现有方法更复杂的特征依赖关系(特征可分为重叠组,且有些组比其他组更重要);以及一个多阶段映射模块,将解释模块生成的基于特征/组的解释转换为适合安全分析师处理的特定领域解释。我们使用基于深度学习的最先进NIDS对EXP-SEC进行评估,结果表明,在组级和重叠感知解释效用指标方面,EXP-SEC优于xNIDS(现有的最佳性能解释框架),而在描述准确性、稀疏性和稳定性等传统特征级指标方面表现相似。此外,以一个基于深度学习的最先进NIDS为例,我们展示了EXP-SEC生成的对安全分析师友好的解释格式。

英文摘要

In this paper, we present EXP-SEC, a novel framework which can explain the intrusion detection decisions of DL-based NIDS (which lead to security alerts) in a way that is aligned with the domain knowledge of analysts working in Security Operations Center (SOC). We highlight the following features of our framework: (1) a forensic module that isolates the suspect packets/flow which likely caused an alert (2) an explanation module which can handle much more complex feature dependencies in network traffic than existing methods (features can be divided into overlapping groups and some groups are more important than others), and (3) a multi-stage mapping module which translates the feature/group-based explanations generated by explanation module to domain-specific explanations suitable for processing by security analysts. We evaluate EXP-SEC with state-of-the-art DL-based NIDS and our evaluation results show that EXP-SEC outperforms xNIDS (existing best performing explanation framework) in terms of group-level and overlap-aware explanation utility metrics while performing similarly in terms of conventional feature-level metrics such as descriptive accuracy, sparsity and stability. Moreover, taking the case of a state-of-the-art DL-based NIDS, we demonstrate the security analyst-friendly explanation format generated by EXP-SEC.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑