论文标题

使用ASTD规格开发用于异常检测的监测系统

Development of monitoring systems for anomaly detection using ASTD specifications

论文作者

Chaymae, El Jabri, Marc, Frappier, Thibaud, Ecarot, Pierre-Martin, Tardif

论文摘要

基于异常的入侵检测系统是针对网络安全威胁的重要防御能力,因为它们可以识别当前活动中的异常情况。但是,这些系统很难通过编程语言提供实体处理独立性。此外,检测过程的退化是由调度训练和检测过程的复杂性引起的,这是保持异常检测系统不断更新所必需的。本文展示了如何使用代数状态转变图(ASTD)语言来开发灵活的异常检测系统。本文提供了一个模型,用于使用无监督的非参数内核密度估计来检测点异常,以估计事件发生的概率密度。提出的模型连续迎合训练和检测阶段。 ASTD语言由于其流程代数运算符提供了解决这些挑战的解决方案,因此简化了检测系统的建模。通过将基于异常的检测过程组合到ASTD语言中,在检测模型开发过程中降低了努力和复杂性。最后,使用定性评估,这项研究表明,ASTD规范语言中的代数运营商克服了这些挑战。

Anomaly-based intrusion detection systems are essential defenses against cybersecurity threats because they can identify anomalies in current activities. However, these systems have difficulties providing entity processing independence through a programming language. In addition, a degradation of the detection process is caused by the complexity of scheduling the training and detection processes, which are required to keep the anomaly detection system continuously updated. This paper shows how to use the algebraic state-transition diagram (ASTD) language to develop flexible anomaly detection systems. This paper provides a model for detecting point anomalies using the unsupervised non-parametric technique Kernel Density Estimation to estimate the probability density of event occurrence. The proposed model caters for both the training and the detection phase continuously. The ASTD language streamlines the modeling of detection systems thanks to its process algebraic operators that provide a solution to overcome these challenges. By delegating the combination of anomaly-based detection processes to the ASTD language, the effort and complexity are reduced during detection models development. Finally, using a qualitative evaluation, this study demonstrates that the algebraic operators in the ASTD specification language overcome these challenges.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源