发表机构
IIT Kharagpur; Clone Systems; IHU; Univ. of Thessaly(印度理工学院克勒格布尔分校; 克隆系统公司; 伊奥尼亚大学; 色萨利大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究提出可解释规则挖掘与阴性对照协议,用于分析IPv6扩展头行为,发现JAMES数据集中主导的Fragment-EH规则实为包内共现而非时间模式,并验证了对照方法的有效性。
AI 中文摘要
IPv6扩展头(EHs),如分片、段路由和随路遥测,在运营上很重要,但在传输中经常被丢弃,从数据包捕获中刻画其行为是一个反复出现的测量问题。我们探究可解释挖掘器能否恢复EH行为的人类可读规则,并贡献了两个可复用工具:一个阴性对照协议,用于诊断挖掘出的“时间”网络规则反映的是真实的跨数据包动态还是仅包内共现;以及一个发送方条件化的、按族分类的EH保留测量。将可解释的时间逻辑规则挖掘器应用于JAMES双视角数据集,我们恢复了一个可移植的Fragment-EH规则,该协议揭示其是包内、近乎定义性的共现而非时间模式,因此时间逻辑机制对此主导规则不起作用;保留测量独立恢复了EH可观测性的预期窗口内顺序。我们的主要结果因此是一个诚实的、受控的阴性发现,并由执行的决策树和大语言模型基线所证实:在所评估的JAMES轨迹上,网络-时间结构不携带主导的Fragment-EH信号,我们提供了确立其何时会携带该信号的对照,并在包含真实跨数据包依赖的合成阳性对照上进行了验证。
英文摘要
IPv6 extension headers (EHs), such as fragmentation, segment routing, and in-situ telemetry, are operationally important yetwidely dropped in transit, and characterising their behaviour from packet captures is a recurring measurement problem. We ask whetheran explainable miner can recover human-readable rules of EH behaviour, and we contribute two reusable tools: a negative-control protocol that diagnoses whether a mined "temporal" network rule reflects genuine cross-packet dynamics or mere within-packetco-occurrence, and a sender-conditioned, per-family EH-retention measurement. Applying an interpretable temporal-logic rule miner to the JAMES paired-vantage dataset, we recover a portable Fragment-EH rule that the protocol reveals to be a within-packet,near-definitional co-occurrence rather than a temporal pattern, so the temporal-logic machinery does no work for this dominant rule;the retention measurement independently recovers the expected within-window ordering of EH observability. Our main result istherefore an honest, controlled negative finding, corroborated by executed decision-tree and large-language-model baselines: on theevaluated JAMES traces network-temporal structure does not carry the dominant Fragment-EH signal, and we supply the controls thatestablish when it would, validated on a synthetic positive control containing a genuine cross-packet dependency.
Comments6 pages, 1 figure, 2 tables. Accepted at the 2026 IEEE International Conference on Cyber Security and Resilience (IEEE CSR 2026)