AI 中文总结
该研究提出多大型语言模型共识框架,评估NIDS基准数据集对银行领域MITRE ATT&CK技术的覆盖度,发现UNSW-NB15覆盖得分最高、CIC-DDoS2019盲区大,为行业化NIDS评估奠定基础并推动银行原生数据集研发。
AI 中文摘要
全球银行网络的系统关键性使其成为高级持续性威胁的高优先级目标,这要求网络入侵检测系统(NIDS)的运行有效性需超出统计准确率范畴。然而,实验中NIDS的性能与实际有效性之间存在显著的验证缺口:在标准基准上达到高准确率的NIDS模型,往往在银行实际环境中失效,因为通用数据集缺乏SWIFT、ATM相关入侵等与实际金融威胁相关的行业特定模式。为解决这一问题,本文研究了一种面向行业的评估方法,系统评估现有NIDS基准数据集对银行基础设施最相关攻击行为的覆盖程度。该方法将MITRE ATT&CK知识库中记录的攻击者行为映射到NIDS基准,同时遵循NIST SP 800-94定义的实际传感器限制。利用包含四个最先进模型的多大型语言模型共识引擎,我们评估了210种银行特定攻击者技术,得出68种网络可观测行为的基线用于系统覆盖分析。对五个基准数据集的评估结果显示,UNSW-NB15的加权覆盖得分最高,为82.2%(尽管仅18.4%反映直接的技术级证据),而CIC-DDoS2019对核心银行行为存在89.9%的盲区。这些发现为面向行业的NIDS评估建立了可复现的基础,并凸显了对银行原生数据集的迫切需求。
英文摘要
The systemic criticality of global banking networks has ren-dered them high-priority targets for advanced persistent threats, neces-sitating Network Intrusion Detection Systems (NIDS) whose operational effectiveness must extend beyond statistical accuracy. However, a signif-icant validation gap persists between experimental NIDS performance and real-world effectiveness: NIDS models that achieve high accuracy on standard benchmarks often fail in operational banking environments because generic datasets lack sector-specific patterns, such as SWIFT and ATM-related intrusions, that characterize real financial threats. To address this, the paper investigates a sector-aware evaluation method-ology that systematically assesses how well existing NIDS benchmark datasets cover the attack behaviors most relevant to banking infrastruc-ture. The methodology maps documented adversary behaviors from the MITRE ATT&CK knowledge base to NIDS benchmarks while enforcing the realistic sensor limitations defined by NIST SP 800-94. Leveraging a multi-LLM consensus engine with four state-of-the-art models, we evalu-ated 210 banking-specific adversary techniques to derive a baseline of 68 network-observable behaviors for systematic coverage analysis. Results across five benchmark datasets demonstrate that UNSW-NB15 achieves the highest utility with an 82.2% weighted coverage score (though only 18.4% reflects direct, technique-level evidence), while CIC-DDoS2019 re-veals an 89.9% blind spot for core banking behaviors. These findings es-tablish a reproducible foundation for sector-aware NIDS evaluation and highlight the urgent need for banking-native datasets.
Comments17 pages