零信任软件定义网络架构中的微分段异常检测
Micro-Segmentation Anomaly Detection in Zero-Trust Software-Defined Network Fabrics
浏览论文内容
中文总结 AI 辅助
该研究针对零信任SDN的异常检测问题,提出ViT和1D-CNN模型,结合微分段技术提升检测性能,实验显示分段输入的模型F1达0.95,ViT略优于1D-CNN。
中文摘要 AI 辅助
零信任架构(ZTA)原则需要严格的网络分段和持续验证,以减少隐式信任和横向威胁传播。本文研究软件定义网络(SDN)系统中的异常检测,采用微分段方法,利用深度学习模型检测规避传统粗粒度监控的有害行为。开发了两个模型:视觉Transformer(ViT)和一维卷积神经网络(1D-CNN),分别用于原始网络流数据和微分段网络流数据。从模拟零信任SDN数据集获得的实验结果表明,微分段可大幅提升检测准确率。在分段输入上训练的模型,准确率和F1分数(F1=0.95)均优于使用未分段原始数据训练的模型(F1=0.90)。基于ViT的检测器略优于1D-CNN,尤其在识别未处理数据中未被察觉的细微横向移动模式方面表现更佳。这些发现凸显了在零信任网络中纳入微分段对提升入侵检测效能的重要性。未来工作将把该方法扩展到包含大规模真实网络数据集和动态在线分段技术。
英文摘要
Zero Trust Architecture (ZTA) principles need rigorous network segmentation and ongoing verification to reduce implicit trust and lateral threat propagation. This paper investigates anomaly detection in software-defined networking (SDN) systems by micro-segmentation, using deep learning models to detect harmful actions that evade traditional coarse-grained monitoring. Two models are developed: a Vision Transformer (ViT) and a 1D Convolutional Neural Network (1D-CNN), which are used to both raw and micro-segmented network flow data. Experimental findings from a simulated zero-trust SDN dataset indicate that micro-segmentation substantially improves detection accuracy. The models trained on segmented input demonstrate enhanced accuracy and F1-scores (F1 = 0.95) compared to those utilizing unsegmented raw data (F1 = 0.90). The ViT-based detector marginally surpasses the 1D-CNN, particularly in recognizing nuanced lateral movement patterns that are unnoticed in unprocessed data. These findings highlight the significance of including micro-segmentation inside zero-trust networks to enhance intrusion detection efficacy. Future efforts will broaden this methodology to include extensive real-world network datasets and dynamic online segmentation techniques.