arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.01250cs.CR

面向主机入侵检测的资源感知行为重构与分层语义学习框架

A Resource-Aware Behavior Reconstruction and Hierarchical Semantic Learning Framework for Host Intrusion Detection

  • Sichuan University(四川大学)
  • School of Cyber Science and Engineering, Sichuan University(四川大学网络空间安全学院)
  • Key Laboratory of Data Protection and Intelligent Management, Ministry of Education, China(教育部数据保护与智能管理重点实验室)
  • Beijing University of Posts and Telecommunications(北京邮电大学)
  • School of Cyberspace Security, Beijing University of Posts and Telecommunications(北京邮电大学网络空间安全学院)
  • China Academy of Information and Communications Technology(中国信息通信研究院)
  • Institute of Security, China Academy of Information and Communications Technology(中国信息通信研究院信息安全研究所)

机构由 AI 辅助整理,请以论文原文为准。

Youli Tao, Rui Tang, Hao Ren, Chengsheng Zhou, Dengzhe Wang, Shuyu Jiang, Xingshu Chen

AI总结:

提出ReSHID框架,通过重构语义连续的系统调用序列并构建主体行为图,利用GATv2学习复杂攻击模式,显著提升主机入侵检测性能并大幅减少特征数量。

AI中文摘要:

系统调用(syscalls)记录了运行程序与操作系统内核之间的关键交互,为部署在云及其他现代计算环境中的主机入侵检测系统(HIDS)提供了细粒度且侵入性最小的数据。然而,现有方法通常按照原始执行顺序对系统调用进行建模,其中来自不同进程的序列交错在一起,使得难以提取有效模式,并引发两个问题:原始系统调用序列能否以产生更具判别性表示的方式重新组织,以及如何从重新组织的序列中有效学习复杂攻击模式。我们提出ReSHID,一种面向主机入侵检测的资源感知行为重构与分层语义学习框架。它通过利用系统调用语义不变量,将跨PID命名空间的主体身份与关系解析建模为二分图匹配问题,并跟踪文件描述符(FD)生命周期以关联指向同一资源的描述符,从而重构语义连续的序列。此外,从这些序列中提取的特征被组织成一个轻量级主体行为图,其中包含主体间关系,GATv2捕获关键协调模式以建模涉及多个主体的复杂攻击。实验结果表明,序列重构与检测方法相结合可以提高HIDS性能。即使使用轻量级线性分类器,所提方法在F1分数(98.64%)、ROC-AUC(99.80%)和PR-AUC(98.10%)方面均达到所有比较方法中的最佳结果,同时与原始序列和MGFE相比,n-gram特征数量分别减少了约75.2%和44.1%。

英文摘要:

System calls (syscalls) record key interactions between running programs and the operating system kernel, providing fine-grained and minimally intrusive data for host-based intrusion detection systems (HIDS) deployed in cloud and other modern computing environments. However, existing methods often model syscalls in their original execution order, where sequences from different processes are interleaved, making informative patterns difficult to extract and raising two questions: whether raw syscall sequences can be reorganized in a way that yields more discriminative representations, and how complex attack patterns can be effectively learned from the reorganized sequences. We propose ReSHID, a resource-aware behavior reconstruction and hierarchical semantic learning framework for host intrusion detection. It reconstructs semantically continuous sequences by leveraging syscall semantic invariants to cast subject identity and relationship resolution across PID namespaces as a bipartite matching problem and tracking file descriptor (FD) lifecycles to associate descriptors referring to the same resource. Additionally, features extracted from these sequences are organized into a lightweight subject behavior graph incorporating inter-subject relationships, where GATv2 captures key coordination patterns to model complex attacks involving multiple subjects. Experimental results show that sequence reconstruction combined with the detection method can improve HIDS performance. Even with a lightweight linear classifier, the proposed method achieves the best results among all compared methods in terms of F1-score (98.64%), ROC-AUC (99.80%), and PR-AUC (98.10%), while reducing the number of n-gram features by approximately 75.2% and 44.1% compared with the raw sequences and MGFE, respectively.

补充信息

↑