AI 中文总结
本文提出Behavioral Grammar架构,用0.88M参数的TinyGPT学习主机行为语法,结合多模块提升检测能力,在AAA威胁下实现93%检测率,建立利于防御者的结构不对称性。
AI 中文摘要
现代端点检测系统面临一个根本矛盾:基于签名的方法极易被多态或自适应威胁规避,而重型深度学习模型则难以审计且难以大规模部署。本文提出Behavioral Grammar(行为语法)检测架构,将主机运行时行为视为结构化语言,通过参数仅0.88M的紧凑因果Transformer(TinyGPT)学习其语法。每个系统事件被离散化为8个token的表示,涵盖事件类型、进程、参数骨架、路径类别、父进程、用户、目标及事件间时序。模型以纯自监督方式学习正常行为的条件分布,异常分数由每个slot的负对数似然(NLL)统计量推导,得出数学上有界的误报率。我们为该先验补充了已知攻击归因的原型学习、基于节奏检测的二阶时序分析、自学习模式提取及五网络融合流水线。针对Adaptive Adversarial Agent(AAA)——一种在防御压力下学习生存策略、执行行为模仿并匹配主机事件率的威胁,我们的系统在3.84%的上线误报率下达到93%的检测率。最强的判别信号并非来自任何单个事件,而是事件间间隔的变异系数:AAA的步进节奏CV为0.310,而良性睡眠间隔的CV为9.786,30倍的差距反映了隐形性与功能性之间的根本权衡。我们将这些发现置于协同进化经济学模型框架内,认为行为语法检测将规避成本从规则规避(低成本)转向分布匹配(高成本),建立了有利于防御者的结构不对称性。
英文摘要
The literature on self-adapting malware is open-loop: adaptation is evaluated against static detectors in simulators, with fitness computed by experimenters. This report closes the loop. We built both sides of the adaptive-malware confrontation and the selection loop between them, measuring four generations of engagement under pre-registered protocols. On the red side, a trained adaptive adversary completes reconnaissance-persistence-exfiltration task chains with zero detections under four concurrent commercial stacks (Microsoft Defender RTP, Falco, Wazuh 4.9.2, Suricata 8.0.3, 52,151 ET Open rules). On the blue side, a behavioral-grammar detector -- a 0.88M Transformer prior over an 8-token event grammar fused with four further detection faces -- catches that adversary at 93% with a 3.84% onboarding false-positive rate. The payoff is a law chain: blacklisting creates no selection pressure (R1: 12 cells, 0 alerts); grammar-level hunting pushes selection onto the adversary's body (R2: 9 morphs, 0% survival); body constants bound the rhythm gene's reachable space (G0: the clamp backfires); and the fourth generation produced the loop's first fit morph -- H7-full, 100% survival across three runs, task chains complete, zero detections in six patrol rounds -- whose genome realizes the two escape axes theory predicted (cap cession; non-hidden landing). A power-latency frontier prices each escape axis (N* ~ 240 events); a network-side sibling firewall shows the method transfers (85/85 attacks, 0.10% FPR); and three structural asymmetries explain why equilibrium favors the defender pressing the propagation plane. The report contains the full engineering detail: laboratory, both organs, frontier, four generations of rounds, complete evaluation (baselines, OOV hard-subset, an honest ADFA-LD negative result, E1-E4 studies), coevolution economics, and registered protocols E-A through E-K.
Comments84 pages. v3: expanded to full technical report incorporating the companion extended submission; corrected references; added public code and data availability (github.com/dahan6/siming, github.com/dahan6/whetstones-lab). Previous versions appeared under the title Behavioral Grammar: Detecting Adaptive Malware via Tiny Language Model Priors and Second-Order Temporal Analysis