增强研究网络的异常恢复能力:用于动态安全基准的大规模预测基准
Enhancing Anomaly Resilience in Research Networks: A Large-Scale Forecasting Benchmark for Dynamic Security Baselining
浏览论文内容
中文总结 AI 辅助
本研究针对研究与教育网络的安全悖论,基于Internet2数据集开展大规模基准测试,提出高保真流量预测框架,采用TiDE等先进架构并引入异常集成策略,提升异常区分度与鲁棒性,为网络安全操作提供支持。
中文摘要 AI 辅助
研究与教育网络(RENs)是科学发现的关键基础设施,但面临独特的安全悖论:其以大规模突发“大象流”为特征的正常流量模式,在统计上与DDoS等 volumetric 攻击对传统监控系统难以区分。这种相似性导致异常检测的误报率很高,使安全操作员无法察觉真正的威胁。在本文中,我们提出并评估了一种高保真流量预测框架,旨在为RENs建立动态安全基准。利用涵盖10个骨干路由器(137亿个数据包)的专属57天Internet2数据集,我们开展了该领域首个异常感知预测模型的大规模基准测试。我们在960种实验配置中系统评估了从SARIMA到最先进的长序列架构(TiDE、PatchTST)的6个模型系列。结果表明,这些先进架构,尤其是TiDE,与传统方法相比可将基准预测误差降低30-42%(p < 0.001),显著提升了合法科学突发与潜在异常的区分度。此外,我们引入了一种新颖的异常集成策略,可在存在噪声时将模型鲁棒性提升3.3%。本研究提供了首个经统计验证的框架,用于区分科学工作流与网络攻击,实现更自主、更具恢复力的网络安全操作。
英文摘要
Research and Education Networks (RENs) serve as critical infrastructure for scientific discovery, yet they face a unique security paradox: their normal traffic patterns which are characterized by massive, bursty "elephant flows" are statistically indistinguishable from volumetric attacks such as DDoS to conventional monitoring systems. This similarity leads to high false-positive rates in anomaly detection, blinding security operators to genuine threats. In this paper, we propose and evaluate a high-fidelity traffic forecasting framework designed to establish dynamic security baselines for RENs. Leveraging an exclusive 57-day Internet2 dataset spanning ten backbone routers (13.7 billion packets), we perform the first large-scale benchmark of anomaly-aware forecasting models in this domain. We systematically evaluate six model families, from SARIMA to state-of-the-art long-sequence architectures (TiDE, PatchTST), across 960 experimental configurations. Our results demonstrate that these advanced architectures, particularly TiDE, reduce baseline prediction error by 30-42% compared to traditional methods ($p < 0.001$), significantly improving the distinction between legitimate scientific bursts and potential anomalies. Furthermore, we introduce a novel anomaly-integration strategy that improves model robustness by 3.3% in the presence of noise. This work provides the first statistically validated framework for distinguishing scientific workflows from network attacks, enabling more autonomous and resilient network security operations.
发表机构
- School of Computing University of Nebraska-Lincoln Lincoln, NE, USA
机构由 AI 辅助整理,请以论文原文为准。