HSMLog:基于小型语言模型辅助的硬件安全模块日志异常检测与行为分析
HSMLog: Small Language Model-Assisted Hardware Security Module Log Anomaly Detection with Behavioral Analysis
浏览论文内容
中文总结 AI 辅助
本文提出HSMLog两阶段框架,结合小型语言模型与检索式行为分析,在真实工业HSM日志上实现98.97%精确率等优异指标,可有效完成HSM日志异常检测与事件分诊。
中文摘要 AI 辅助
硬件安全模块(HSM)日志捕获与安全相关的行为,但异常源于事件序列、密钥、对象状态、会话及时间模式之间的关联,而非孤立事件。现有方法将检测与HSM特定证据验证、报告分离。本文提出HSMLog,这是一个基于检索的行为分析的HSM日志异常检测两阶段框架。第一阶段,小型语言模型(SLM)从结构化HSM事件的滑动窗口中识别候选告警,并使用HSM特定操作规则执行策略引导的评估。第二阶段,检索到的策略、告警窗口之前的历史可疑密钥记录,以及与候选相关的日志上下文,共同支持保守的候选审查和事件分析。在工业伙伴共同定义异常场景的真实工业HSM背景日志上评估,HSMLog达到98.97%的精确率、96.00%的召回率、98.66%的异常事件覆盖率和97.46%的F1分数,在研究场景中展现出有效的异常告警和事件分诊能力。
英文摘要
Hardware Security Module (HSM) logs capture security-critical behavior, but anomalies emerge from relationships across event sequences, keys, object states, sessions, and temporal patterns rather than isolated events. Existing methods separate detection from HSM-specific evidence validation and reporting. In this paper, we present HSMLog, a two-stage framework for HSM log anomaly detection with retrieval-grounded behavioral analysis. In Stage 1, a small language model (SLM) identifies candidate alerts from sliding windows of structured HSM events and performs policy-guided assessment using HSM-specific operational rules. In Stage 2, retrieved policies and historical suspicious-key records strictly predating the alert window, together with candidate-related log context, support conservative candidate review and incident analysis. Evaluated on real industrial HSM background logs augmented with anomaly scenarios co-defined with industrial partners, HSMLog achieves 98.97% precision, 96.00% recall, 98.66% anomalous-event coverage, and a 97.46% F1 score, demonstrating effective anomaly alerting and incident triage in the studied setting.
发表机构
- National Taiwan University(台湾大学)
- National Taiwan University of Science and Technology(台湾科技大学)
机构由 AI 辅助整理,请以论文原文为准。