发表机构
Laboratoire de Recherche de l’EPITA; Université de Strasbourg(EPITA研究实验室; 斯特拉斯堡大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对网络流量检测中的概念漂移问题,提出基于社区与谱图分析的t-鲁棒性特征选择方法,在UGR16数据集上显著优于基线,维持检测性能。
AI 中文摘要
在网络流量中,合法行为与攻击技术会共同演化——这一现象被称为“概念漂移”[1]。因此,每个检测器在两次更新之间都会变得过时,并且总是落后于攻击者一步。在这项工作中,我们提出将干预点从模型(在漂移后修复)转移到特征空间(在学习前选择)。为此,我们引入了t-鲁棒性,这是一个为每个特征独立定义的稳定性分数,不依赖于任何检测模型,并且可在整个特征空间中进行比较。它结合了特征连续统计状态之间的逐步距离,以及其相对于初始状态的累积偏差,从而使得缓慢的单调漂移不能被视为稳定。候选特征来源于扫描、拒绝服务攻击和端点间通信留下的异常网络连接模式,这些模式通过图社区指标和谱指标读取。评估在UGR16数据集上进行,涵盖三种学习场景和一种控制场景,以及无模型更新的情况,结果表明t-鲁棒特征空间在基线崩溃时仍能维持检测性能:在最后一个测试区间,保留期望达到0.6025,而图社区特征为0.5230,基础NetFlow特征为0.3831。
英文摘要
In network traffic, legitimate behaviours and attack techniques evolve jointly - the phenomenon known as 'concept drift' [1]. Every detector is thereby left obsolete between two updates, and always one step behind adversaries. In this work, we propose to move the point of intervention from the model, repaired after the drift, to the feature space, selected before learning. We therefore introduce t-robustness, a stability score defined for each feature independently of any detection model, comparable across an entire feature space. It combines the step-by-step distance between successive statistical states of a feature, and its cumulative divergence from its initial state, so that a slow monotonic drift cannot pass for stability. The candidates are drawn from abnormal network connectivity patterns left by scans, DoS and communications between endpoints, read through graph community metrics and spectral metrics. The evaluation is performed on the UGR16 dataset, across three learning scenarios and a control scenario, as well as without model update, and demonstrate that t-robust feature spaces sustain detection where the baselines collapse: retained expectancy at the last test interval reaches 0.6025, against 0.5230 for graph community features and 0.3831 for the base NetFlow features.