AI 中文总结
该研究提出网络入侵检测系统Slips,通过构建主机行为轮廓、模块化架构聚合证据,在PCAP数据集上较Suricata召回率高83%、F1高70%,实现更贴合专家判断的情境感知决策。
AI 中文摘要
网络入侵检测系统通常分析单个数据包或流,尽管恶意行为可能会在多个连接和一段时间内发展,这可能会限制它们将孤立的检测结果整合为对主机行为的连贯评估的能力。数据包级特征对于基于复杂人工智能的检测而言可能过于底层,需要额外处理以在保持低误报率的同时提高准确性。我们提出了Slips,这是一种网络入侵检测系统,它构建以主机为中心的行为轮廓,并将活动组织到时间窗口中。它采用模块化架构,其中独立模块报告证据而非直接生成最终警报,随后Slips将这些证据累积为主机级决策。我们在专家标记的PCAP数据集上针对Suricata评估了Slips。在轮廓时间窗口级别,Slips的召回率比Suricata高83%,F1分数高70%,且两个系统均未产生误报。这些结果表明,基于时间窗口的证据聚合可以产生与专家判断更一致的情境感知决策。
英文摘要
Network intrusion detection systems often analyze individual packets or flows, although malicious behavior may develop across many connections and over time. This may limit their ability to combine isolated detections into a coherent assessment of host behavior. Packet-level features may also be too low-level for complex AI-based detection, requiring additional processing to improve accuracy while maintaining a low false-positive rate. We present Slips, a network intrusion detection system that builds host-centered behavioral profiles and organizes activity into time windows. It uses a modular architecture in which independent modules report evidence rather than generating final alerts directly. Slips then accumulates this evidence into host-level decisions. We evaluate Slips against Suricata on an expert-labeled PCAP dataset. At the profile-time-window level, Slips achieved 83% higher recall and a 70% higher F1 score than Suricata, while neither system produced false positives. These results indicate that time-window-based evidence accumulation can produce context-aware decisions that better align with expert judgment.