亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

Fusing Security Alerts Improves Cyber-Security: An Alert Normalization Framework for Heterogeneous Devices

计算机科学 规范化(社会学) 计算机安全 网络空间 假阳性悖论 网络安全 人工智能 互联网 万维网 人类学 社会学
作者
Songxuan Wei,Y. G. Xie,Angxiao Zhao,Jing Xiao,Cui Luo,Zhaoquan Gu
标识
DOI:10.1109/dsc59305.2023.00011
摘要

With the rapid development of network technologies, cyberspace security is facing increasingly complex threats. To detect and respond to the rapidly growing number of network attacks, many security devices are widely adopted. However, a single security device often detects network attacks based on a single algorithm or some pre-defined features, resulting in a large number of false positives and false negatives in the security alerts it generates. Hence, many heterogeneous security devices are normally used; and fusing the alerts from these devices is an effective way to improve the quality of security alerts. As the formats or even the contents of the reported alerts are quite different, it has become a severe problem to fuse these alerts in practice. To address this problem, we propose an alert normalization framework in this paper for multi-source heterogeneous devices, which can convert different alert types reported by heterogeneous devices into a unified attack classification system automatically, making it possible to jointly analyze these alerts. Our framework extracts keywords describing each attack type by calculating the TF-IDF value, and then uses the normalized TF-IDF value as a weight to predict which attack type the alert belongs to. Experiments on 67,957 security alerts obtained from 15 security devices show that our method has good performance and is well interpretable. In addition, it can predict unseen alerts with a high accuracy of 0.65.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
6秒前
loii完成签到,获得积分0
7秒前
13秒前
ruanyousong完成签到,获得积分10
14秒前
15秒前
自然如冰发布了新的文献求助10
16秒前
Akim应助小小采纳,获得10
18秒前
小小完成签到,获得积分10
30秒前
Zhou发布了新的文献求助10
31秒前
32秒前
大个应助tfop采纳,获得10
32秒前
小小发布了新的文献求助10
36秒前
45秒前
李健的粉丝团团长应助Zhou采纳,获得10
50秒前
tfop发布了新的文献求助10
50秒前
MchemG应助科研通管家采纳,获得30
51秒前
MchemG应助科研通管家采纳,获得30
51秒前
gg完成签到 ,获得积分10
55秒前
1分钟前
我是老大应助tfop采纳,获得10
1分钟前
1分钟前
1分钟前
tfop发布了新的文献求助10
1分钟前
Layover完成签到 ,获得积分10
2分钟前
2分钟前
2分钟前
orixero应助科研通管家采纳,获得10
2分钟前
2分钟前
arizaki7发布了新的文献求助10
2分钟前
烟花应助arizaki7采纳,获得10
3分钟前
科研通AI6.3应助tfop采纳,获得10
3分钟前
arizaki7完成签到,获得积分20
3分钟前
3分钟前
tfop发布了新的文献求助10
3分钟前
4分钟前
4分钟前
充电宝应助tfop采纳,获得10
4分钟前
4分钟前
酷波er应助科研通管家采纳,获得10
4分钟前
4分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Chemistry and Physics of Carbon Volume 18 800
The Organometallic Chemistry of the Transition Metals 800
The formation of Australian attitudes towards China, 1918-1941 640
Signals, Systems, and Signal Processing 610
天津市智库成果选编 600
全相对论原子结构与含时波包动力学的理论研究--清华大学 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6444446
求助须知:如何正确求助?哪些是违规求助? 8258368
关于积分的说明 17591080
捐赠科研通 5503672
什么是DOI,文献DOI怎么找? 2901402
邀请新用户注册赠送积分活动 1878421
关于科研通互助平台的介绍 1717736