arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.26831cs.CR

当关系破裂时:通过依赖关系违规解释网络流量异常

When Relationships Break: Interpreting Network Traffic Anomalies via Dependency Violations

Federica Uccello, Simin Nadjm-Tehrani

AI总结:

本研究提出XION方法,通过建模网络流特征间的依赖关系来检测异常并解释警报,在IDS数据集上与IF相比,召回率相当或更高且推理时间更短,还能提供IF无法给出的攻击相关时间结构模式。

AI中文摘要:

当前安全监控领域的研究越来越关注基于机器学习的方法,但仍存在一些需要注意的问题。除了巨大的计算开销外,一个核心担忧是缺乏警报触发原因的可解释性。现有的可解释性方法要么依赖于忽略特征间依赖关系的特征归因方法,要么依赖于需要大量领域知识或计算资源的因果建模。本研究提出了XION,一种仅基于良性流量对网络流特征间关系进行建模的方法。在检测过程中,异常通过预期特征依赖关系的违规来识别。此外,XION支持警报后分析,可识别哪些特征关系发生破裂、在攻击时间线的哪个节点发生破裂,以及依赖关系违规相对于其他已识别违规的演变情况。研究在标准入侵检测系统(IDS)数据集上对XION进行评估,并与孤立森林(Isolation Forest, IF)基线在多种攻击场景(包括流量型攻击和更隐蔽的攻击)中进行比较。结果显示,在所有评估场景中,XION的召回率与IF相当或更高,同时推理时间最多减少7倍。在警报后阶段,依赖关系违规分析揭示了与已知攻击行为一致的时间和结构模式,这是仅使用IF无法提供的。这些发现共同证实,攻击确实会破坏从良性流量中学习到的特征依赖关系,而这些破坏为理解警报提供了额外信息。

英文摘要:

Current research on security monitoring is increasingly focusing on machine-learning-based approaches, but caveats remain. In addition to huge computational overhead, one concern is the lack of insights into "why" alerts are raised. Existing interpretability approaches rely on feature attribution methods that ignore dependencies among features or on causal modeling that requires extensive domain knowledge or computational resources. This work proposes XION, a method for modeling relationships among network-flow features based on benign traffic only. During detection, anomalies are identified through violations of expected feature dependencies. Further, XION supports post-alert analysis by identifying which feature relationships break, when they break along the attack timeline, and how dependency violations evolve relatively to other identified violations. XION is evaluated on standard IDS datasets and compared against an Isolation Forest (IF) baseline across multiple attack scenarios, including both volumetric and stealthier attacks. Results show that XION matches or exceeds IF recall in all evaluated scenarios, while requiring up to 7x less inference time. At the post-alert stage, the dependency-violation analysis reveals temporal and structural patterns consistent with known attack behaviors, which IF alone could not contribute to. Together, these findings confirm that attacks indeed disrupt feature dependencies learned from benign traffic, and that these disruptions provide additional information for understanding an alert.

↑