发表机构
Xidian University; University of Padova(西安电子科技大学; 帕多瓦大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对现有PIDS统一对待关系而忽视统计异质性的问题,提出RECAL框架,通过关系平衡掩码图学习与误差校准,在DARPA E3数据集上显著提升F1分数并大幅降低误报率。
AI 中文摘要
基于溯源的入侵检测系统(PIDSs)通过分析系统交互来检测高级持续性威胁(APTs)。然而,现有方法大多统一对待关系,忽视了统计异质性;在CADETS中,关系频率差异约为140,000倍。这可能导致PIDSs更关注频繁关系,而忽视不同关系间正常错误水平的差异,增加误报和漏报的风险。我们提出RECAL,一种无监督框架,采用关系平衡的掩码图学习以更好地捕获稀有交互模式。它进一步根据每种关系的良性错误分布校准重建误差,以产生可比较的异常证据,帮助区分攻击与良性行为并减少误报。在三个DARPA E3数据集上,RECAL的F1分数分别达到99.99%、99.93%和99.99%,在每个数据集上分别比最佳基线高出0.88、0.82和0.42个百分点。与报告最低假阳性率(FPR)的基线相比,RECAL将平均FPR分别降低了约105倍、4倍和41倍。
英文摘要
Provenance-Based Intrusion Detection Systems (PIDSs) detect Advanced Persistent Threats (APTs) by analyzing system interactions. However, existing methods largely treat relations uniformly, overlooking statistical heterogeneity; in CADETS, relation frequencies differ by approximately $140{,}000\times$. This may cause PIDSs to focus more on frequent relations and overlook differences in normal error levels across relations, increasing the risk of false alarms and missed detections. We present RECAL, an unsupervised framework using relation-balanced masked graph learning to better capture rare interaction patterns. It further calibrates reconstruction errors against each relation's benign error distribution to produce comparable anomaly evidence, helping distinguish attacks from benign behavior and reduce false alarms. On three DARPA E3 datasets, RECAL achieves F1 scores of 99.99\%, 99.93\%, and 99.99\%, outperforming the best baseline on each dataset by 0.88, 0.82, and 0.42 percentage points, respectively. Compared with the baseline reporting the lowest FPR, RECAL reduces mean FPR by approximately $105\times$, $4\times$, and $41\times$.
Comments5 pages