An Explainable Intelligence Model for Security Event Analysis

An Explainable Intelligence Model for Security Event Analysis
复制标题

安全事件分析的可解释情报模型

DOI:
--
复制
发表时间:
2019
期刊:
Australasian Conference on Artificial Intelligence
影响因子:
--
通讯作者:
Yuan Miao
Yuan Miao
中科院分区:
--
文献类型:
--
作者:
Neda Afzaliseresht;Qing Liu;Yuan Miao

文献摘要

被引文献

相似文献

监控系统记录了大量的事件。在事件发生之前,分析师不会审计或跟踪记录最重要事件的日志文件。人工分析是一项乏味且不准确的任务,因为有大量的日志文件以“机器友好”的格式存储。分析人员必须使用先验知识推导出事件的背景,以找到与事件相关的事件,以识别事件发生的原因。虽然通过提供可视化技术和最大限度地减少人类交互来开发安全工具,以使分析过程更容易,但对以“人类友好”的形式解释安全事件的关注太少。此外,目前的检测模式和规则还不够成熟,无法识别尚未造成任何损害的早期违规行为。在本文中,我们提出了一个可解释的人工智能模型,帮助分析人员从安全事件日志中推断发生了什么。提出的可解释人工智能模型包括讲故事作为一种新的知识表示模型,以呈现从日志文件中自动发现的事件序列。对于序列事件的自动发现,使用了一种通过挖掘时间模式来实现类先验性的算法。这项工作的重点是安全事件,以传达短寿命和长寿命活动。实验结果表明,本文提出的可解释人工智能模型在Windows系统安全配置合规过程中的安全日志验证中具有一定的潜力和优势。
Huge volume of events is logged by monitoring systems. Analysts do not audit or trace the log files, which record the most significant events, until an incident occurs. Human analysis is a tedious and inaccurate task given the vast volume of log files that are stored in a “machine-friendly” format. The analysts have to derive the context for an incident using the prior knowledge to find relevant events to the incident to recognise why it has happened. Although the security tools by providing visualization techniques and minimizing human interactions have been developed to make the process of analysis easier, far too little attention has been paid to interpret security incident in a “human-friendly” format. Besides, the current detection patterns and rules are not mature enough to recognize early breaches, which have not caused any damage. In this paper, we presented an Explainable AI model that assist the analysts’ judgement to infer what is happened from the security event logs. The proposed Explainable AI model includes storytelling as a novel knowledge representation model to present the sequence of the events which automatically are discovered from the log file. For automated discovering sequential events, an apriority-like algorithm by mining temporal patterns is utilized. This effort focused on security events to convey both short-life and long-life activities. The experimental results demonstrate the potential and advantages of the proposed Explainable AI model from the security logs that validated on the activities during the security configuration compliance on Windows system.