DAEMON: Dynamic Auto-encoders for Contextualised Anomaly Detection Applied to Security MONitoring

IFIP International Information Security Conference (SEC)(2022)

引用 2|浏览12
暂无评分
摘要
The slow adoption rate of machine learning-based methods for novel attack detection by Security Operation Centers (SOC) analysts can be partly explained by their lack of data science expertise and the insufficient explainability of the results provided by these approaches. In this paper, we present an anomaly-based detection method that fuses events coming from heterogeneous sources into sets describing the same phenomenons and relies on a deep auto-encoder model to highlight anomalies and their context. To implicate security analysts and benefit from their expertise, we focus on limiting the need of data science knowledge during the configuration phase. Results on a lab environment, monitored using off-the-shelf tools, show good detection performances on several attack scenarios (F1 score approximate to 0.9), and eases the investigation of anomalies by quickly finding similar anomalies through clustering.
更多
查看译文
关键词
Anomaly detection,Heterogeneous log analysis,Human-automation cooperation,Intrusion detection,Machine learning
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要