arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

基于时间序列分析的网络电磁异常检测

Cyber-Electromagnetic Anomaly Detection Through Time-Series Analysis

María Teresa Guillén Navarro, Juan Luis Serradilla Tormos, Sergio López Bernal, Daniel Díaz-López, Gregorio Martínez Pérez

arXiv 2608.27043首次发表:更新:

AI 中文总结

该研究针对网络电磁异常检测的单视角局限,结合ZBDS2023数据集的双域特征,构建随机森林监督模型与LSTM-Autoencoder无监督模型,实现了对网络电磁异常的有效检测,为网络态势感知提供支撑。

AI 中文摘要

军事行动得益于动能域与非动能域的协同,其中网络作战与电磁战的协同对获取作战优势愈发重要,该协同也与网络态势感知(CSA)相关,而观察-定向-决策-行动(OODA)环需要监测和解释来自异构源的证据。在此背景下,异常不仅可能出现在信号的物理行为中,还可能出现在流量层面观测到的通信行为中。然而,许多现有异常检测方案仅关注其中一个视角,限制了其对同时在电磁频谱和网络空间中显现的事件的表征能力。为解决这一局限,本研究开发并评估了两种结合两个域特征的异常检测模型。更具体地说,研究使用ZBDS2023数据集,该数据集包含网状网络节点的流量,涵盖良性和攻击行为,提供了物理层面特征、流量层面特征及带标签的攻击。评估的两种检测方法为:基于随机森林(Random Forest)的监督模型和使用长短期记忆自动编码器(LSTM-Autoencoder)的无监督模型。结果显示,基于学习的模型可检测结合两个层面的模式,尤其是在监督方法下,随机森林的F1分数达89.76%,LSTM-Autoencoder的F1分数达64.09%。尽管这些结果表明所提出的模型可通过改进对异常行为的观测和解释来支持网络态势感知,但正常样本与攻击样本之间的细微差异凸显了对更丰富判别特征的需求。

英文摘要

Military operations benefit from the coordination between kinetic and non-kinetic domains. In particular, the coordination of cyber operations and electromagnetic warfare has become increasingly relevant for gaining operational advantage. This coordination is also relevant for Cyber Situational Awareness (CSA), where the Observe-Orient-Decide-Act (OODA) loop requires monitoring and interpreting evidence from heterogeneous sources. In this context, anomalies may appear not only in the physical behavior of signals, but also in the communication behavior observed at the traffic level. However, many existing anomaly detection proposals focus on only one of these perspectives, limiting their ability to characterize events that manifest simultaneously in the electromagnetic spectrum and cyberspace. To address this limitation, this work develops and evaluates two anomaly detection models that combine features from both domains. More specifically, the study uses the ZBDS2023 dataset, which contains traffic from nodes in a mesh network, including benign and attack behaviors. Thus, this dataset provides physical-level features, traffic-level features, and labeled attacks. Two detection approaches are evaluated: a supervised model based on Random Forest and an unsupervised model using LSTM-Autoencoder. The results show that learning-based models can detect patterns combining both levels, especially under a supervised approach, achieving an F1-score of 89.76% with Random Forest and 64.09% with LSTM-Autoencoder. Although these results indicate that the proposed models can support CSA by improving the observation and interpretation of anomalous behavior, the subtle differences between normal and attack samples highlight the need for richer discriminative features.

Comments18 pages, 4 figures, 11 tables, paper in proceedings of The International Conference on Availability, Reliability and Security, ARES 2026 in Linkoping, Sweden, August 2026

DOI:10.1007/978-3-032-35579-9_18

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑