节点文献

基于重叠社区发现和图序列化的溯源入侵检测方法

A Provenance Intrusion Detection Method Based on Overlapping Community Discovery and Graph Serialization

【作者】 张海霞;

【导师】 谢雨来;

【作者基本信息】 华中科技大学 , 网络空间安全, 2023, 硕士

【摘要】 随着网络环境愈发复杂,攻击者的攻击手段越来越多样化,并且擅长于将攻击操作隐藏在大量正常操作中。而传统基于主机的溯源入侵检测方法往往以整个用户行为为分析单元,无法从海量的数据中精准挖掘异常操作特征,难以准确识别出异常行为。为解决当前存在的问题,提出了基于重叠社区发现和图序列化的溯源入侵检测方法,以组成用户行为的行为实例为分析单元并在最小化信息丢失的条件下将各行为实例送入神经网络深入挖掘特征,以完成高效精准的异常行为检测。首先,设计了新颖的重叠社区发现算法来充分准确合理的划分行为实例,综合考虑节点依赖关系及其自身属性来衡量节点在溯源图的重要性并以此作为社区划分的重要依据,根据节点与相邻社区的关联度来判断是否存在重叠社区。然后,采用节点聚合来改进图序列化算法以在序列化行为实例时最大化保留溯源信息。接着,提出基于卷积的自编码器对序列化后的行为实例进行特征提取。最后,运用二分K-means聚类算法对各用户行为的特征进行聚类并保存聚类结果作为特征代表。通过获得待检测行为的特征代表与规则库的余弦相似度来判断用户行为是否存在异常。通过在来自不同溯源追踪系统的9种应用数据集上进行实验,提出的Perseus相比于传统以用户行为为分析单元的入侵检测方法FRAP、Pagoda、UNICORN在精确率(Precision)分别平均提高了0.42、0.579、0.027;在召回率(Recall)提高了0、0.3、0.02;在准确率(Accuracy)提高了0.4、0.53、0.017;在F1-score提高了0.276、0.486、0.016。同时,Perseus具有较小的时间开销和空间开销。

【Abstract】 As network environments become more complex,attackers are becoming more and more sophisticated in their attack methods,specializing in hiding attacks within a large number of normal operations.However,traditional host-based provenance intrusion detection methods tends to take the entire user behavior as the unit of analysis and cannot accurately mine the abnormal operation characteristics from the massive data,making it difficult to accurately identify abnormal behavior.To address the current problems,a provenance intrusion detection method based on overlapping community discovery and graph serialization called Perseus is proposed.The method uses the behavioural instances that comprise the user’s behaviour as the unit of analysis,and feeds each behavioural instance into the neural network to mine features in depth with minimal information loss,thus achieving efficient and accurate anomalous behaviour detection.Firstly,a novel overlapping community discovery algorithm is designed to divide the behavioral instances that constitute user behavior with sufficient Accuracy and rationality.The algorithm combines the dependencies of nodes and their attributes to measure the importance of nodes in the provenance graph as an essential basis for community delineation.Besides,it discriminates the existence of overlapping communities based on the association of nodes with neighboring communities.Next,node aggregation is used to improve the graph serialization algorithm to maximize the retention of provenance information when serializing behavioral instances.Then,a convolutionbased auto-encoder is proposed for feature extraction of the serialized behavioral instances.Finally,the dichotomous K-means clustering algorithm is used to cluster the features of each user’s behavior and save the clustering results as feature representatives.By obtaining the cosine distance between the feature representation of the behavior to be detected and the rule base,it is determined whether the behavior is anomalous or not.This accomplishes efficient and accurate intrusion detection.By conducting experiments on nine application datasets from different provenance tracking systems,the proposed method Perseus,compared to the traditional intrusion detection methods FRAP,Pagoda,and UNICORN,which use user behavior as the unit of analysis,showed average improvements of 0.42,0.579 and 0.027 in Precision;0,0.3 and0.02 in Recall;0.4,0.53,0.017 in Accuracy;and 0.276,0.486 and 0.016 in F1-score.In addition,Perseus has a low time and memory overhead.

  • 【分类号】TP393.08;O157.5
节点文献中: 

本文链接的文献网络图示:

本文的引文网络