发表机构
Sandia National Laboratory(桑迪亚国家实验室)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
研究针对网络安全中恶意异常活动检测难题,提出混合潜在结构融合(HLSF)框架,整合CP-APR结构异常分数与归一化流潜在空间密度分数,实验证明该框架能提升在特定数据集上的异常检测性能。
AI 中文摘要
恶意异常活动检测是网络安全系统面临的一项基本挑战。基于统计框架的张量分解(如CANDECOMP-PARAFAC交替泊松回归,CP-APR)和归一化流已被证明是强大的无监督机器学习方法,可对多维数据建模并捕捉网络安全应用中行为特征的复杂多面细节。本研究提出混合潜在结构融合(HLSF),这是一个将CP-APR结构异常分数与归一化流导出的潜在空间密度分数相结合的加权异常融合框架。实验表明,与单独使用CP-APR或归一化流相比,HLSF框架在从洛斯阿拉莫斯国家实验室(LANL)大型企业网络红队演习中收集的真实世界受损用户凭证数据集上提高了异常检测性能。
英文摘要
Malicious anomalous activity detection is a fundamental challenge for cyber security systems. Both tensor decomposition under statistical framework with CANDECOMP-PARAFAC alternating Poisson regression (CP-APR) and normalizing flows have proven to be powerful unsupervised machine learning methods that model multi-dimensional data and capture complex and multi-faceted details of behavior profiles in cyber security applications. In this study, we propose Hybrid Latent-Structural Fusion (HLSF), a weighted anomaly fusion framework integrating CP-APR structural anomaly scores with latent-space density scores derived from normalizing flows. In our experiments, we show that the HLSF framework improves anomaly detection performance on a dataset of real-world compromised user credentials collected from the large enterprise network of Los Alamos National Laboratory (LANL) during a red-teaming exercise, compared with using CP-APR or normalizing flows alone.