Interpretable Federated Transformer Log Learning for Cloud Threat Forensics

Interpretable Federated Transformer Log Learning for Cloud Threat Forensics
复制标题

DOI:
10.14722/ndss.2022.23102
复制
发表时间:
2022
期刊:
Proceedings 2022 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
G. Parra;Luis Selvera;Joseph Khoury;Hector Irizarry;E. Bou-Harb;P. Rad
G. Parra;Luis Selvera;Joseph Khoury;Hector Irizarry;E. Bou-Harb;P. Rad
中科院分区:
其他
文献类型:
--
作者:
G. Parra;Luis Selvera;Joseph Khoury;Hector Irizarry;E. Bou-Harb;P. Rad

文献摘要

相似文献

-威胁检测和取证已成为任何数字取证分类的重要目标。已经提出了用于推断系统和网络异常的监督方法;包括使用syslog日志的异常检测贡献。然而,大多数研究都淡化了模型决策过程可解释性的重要性。在这项研究中,我们首先提出了一个可解释的联合变压器日志学习模型,用于支持可解释的网络取证的威胁检测。提出的模型是通过在组织单元中的每个客户端训练一个基于本地变压器的威胁检测模型来生成的。本地模型从保存执行流记录的syslog日志中学习系统的正常行为。随后,联邦学习服务器聚合来自本地模型的学习模型参数,以生成全局联邦学习模型。捕获正常行为的日志时间序列预计与拥有网络威胁活动的日志时间序列不同。我们通过基于卡尔-皮尔逊卡方统计量的拟合优度检验来证明这种差异。为了深入了解触发这种差异的行为,我们集成了一个基于注意力的可解释性模块。我们使用HDFS(一个公开可用的日志数据集)和一个内部收集并公开发布的名为CTDD的数据集来实现和评估我们提出的模型,该数据集由超过800万条syslog日志组成,代表了云协作服务和受到不同类型网络威胁的系统。此外,通过不同的实验,我们证明了日志不可知能力和我们的方法在现实世界的操作设置(如边缘计算系统)上的适用性。我们的可解释性模块体现了正常和异常日志之间显著的注意差异,为模型的决策过程提供了深刻的可解释性。最后,我们将获得的结果视为在现实世界中适当采用我们的方法来实现威胁取证的验证。
—Threat detection and forensics have become an imperative objective for any digital forensic triage. Supervised approaches have been proposed for inferring system and network anomalies; including anomaly detection contributions using syslogs. Nevertheless, most works downplay the importance of the interpretability of a model’s decision-making process. In this research, we are among the first to propose an interpretable federated transformer log learning model for threat detection supporting explainable cyber forensics. The proposed model is generated by training a local transformer-based threat detection model at each client in an organizational unit. Local models learn the system’s normal behavior from the syslogs which keep records of execution flows. Subsequently, a federated learning server aggregates the learned model parameters from local models to generate a global federated learning model. Log time-series capturing normal behavior are expected to differ from those possessing cyber threat activity. We demonstrate this difference through a goodness of fit test based on Karl-Pearson’s Chi-square statistic. To provide insights on actions triggering this difference, we integrate an attention-based interpretability module. We implement and evaluate our proposed model using HDFS, a publicly available log dataset, and an in-house collected and publicly-released dataset named CTDD, which consists of more than 8 million syslogs representing cloud collaboration services and systems compromised by different classes of cyber threats. Moreover, through different experiments, we demonstrate the log agnostic capability and applicability of our approach on real-world operational settings such as edge computing systems. Our interpretability module manifests significant attention difference between normal and abnormal logs which provide insightful interpretability of the model’s decision-making process. Finally, we deem the obtained results as a validation for the appropriate adoption of our approach in achieving threat forensics in the real world.