On the Variety and Veracity of Cyber Intrusion Alerts Synthesized by Generative Adversarial Networks

On the Variety and Veracity of Cyber Intrusion Alerts Synthesized by Generative Adversarial Networks
复制标题

关于生成对抗网络合成的网络入侵警报的多样性和准确性

DOI:
10.1145/3394503
复制
发表时间:
2020
影响因子:
2.5
通讯作者:
Yang, Shanchieh
Yang, Shanchieh
中科院分区:
--
文献类型:
--
作者:
Sweet, Christopher Ryan;Moskal, Stephen;Yang, Shanchieh

文献摘要

参考文献

相似文献

可以观察到许多网络攻击行为,但可观察量通常表现出复杂的特征依赖性,非同质性以及潜在的稀有但关键的样本。这项工作测试了通过生成对抗网络(GAN)学习,建模和合成网络入侵警报的能力,GAN通过在随机生成的样本和反映不同攻击行为混合的数据之间进行协调来探索特征空间。通过使用Jensen-Shannon散度,条件熵和联合熵以及模式下降和增加的综合分析,我们表明,具有梯度惩罚和互信息的Wasserstein-GAN在学习生成现实警报方面比没有互信息约束的模型更有效。我们进一步表明,添加的互信息约束推动模型更彻底地探索特征空间,并增加了低概率但关键的警报特征的生成。这项研究展示了无监督GAN的新颖和有前途的应用,可以从有限但多样的入侵警报中学习,生成模拟关键依赖关系的合成警报,为主动的数据驱动的网络威胁分析打开大门。
Many cyber attack actions can be observed, but the observables often exhibit intricate feature dependencies, non-homogeneity, and potentially rare yet critical samples. This work tests the ability to learn, model, and synthesize cyber intrusion alerts through Generative Adversarial Networks (GANs), which explore the feature space by reconciling between randomly generated samples and data that reflect a mixture of diverse attack behaviors withouta prioriknowledge. Through a comprehensive analysis using Jensen-Shannon Divergence, Conditional and Joint Entropy, and mode drops and additions, we show that the Wasserstein-GAN with Gradient Penalty and Mutual Information is more effective in learning to generate realistic alerts than models without Mutual Information constraints. We further show that the added Mutual Information constraint pushes the model to explore the feature space more thoroughly and increases the generation of low probability, yet critical, alert features. This research demonstrates the novel and promising application of unsupervised GANs to learn from limited yet diverse intrusion alerts to generate synthetic alerts that emulate critical dependencies, opening the door to proactive, data-driven cyber threat analyses.
KDD Cup 99数据集存在的问题及数据预处理
DOI: --
发表时间: 2014
期刊:
影响因子: --
作者:
Yan Wang;Kun Yang;Xiang Jing;Huang Jin
通讯作者: Huang Jin
DOI: --
发表时间: 2019
期刊:
影响因子: --
作者:
Christopher Sweet
通讯作者: Christopher Sweet
使用 GAN 生成对话
DOI: 10.1609/aaai.v32i1.12158
发表时间: 2018
期刊: Comput. Networks
影响因子: --
作者:
Hui Su;Xiaoyu Shen;Pengwei Hu;Wenjie Li;Yun Chen
通讯作者: Yun Chen
DOI: --
发表时间: 2018-12
期刊: ArXiv
影响因子: --
作者:
Idan Amit;John Matherly;W. Hewlett;Zhi Xu;Yinnon Meshi;Yigal Weinberger
通讯作者: Idan Amit;John Matherly;W. Hewlett;Zhi Xu;Yinnon Meshi;Yigal Weinberger