预算受限的零日网络威胁缓解框架:以知识为导向的强化学习方法
1School of Computer Engineering & Applied Mathematics, Hankyong National University, Anseong-si 17579, Republic of Korea.
Sensors (Basel, Switzerland)
|January 10, 2026
概括
本研究介绍了一种基于知识的新型网络防御框架,可以提高对未知的网络攻击的检测. 该系统在预算限制范围内提高了准确性和可解释性,优于传统方法.
科学领域:
- 网络安全 网络安全
- 人工智能的人工智能
- 知识表示 知识表示
背景情况:
- 传统的机器学习防御与新型攻击链斗争,缺乏可解释性.
- 有限的遥测预算阻碍了当前系统的效率和审计能力.
研究的目的:
- 开发基于知识的网络防御框架,以更好地检测零日攻击.
- 整合ATT&CK (对抗战术,技术和共同知识) 的受限制生成,受预算限制的强化学习和因果解释.
主要方法:
- 使用语法正式化的ATT&CK数据库正式化攻击链合成.
- 将攻击编译成Zeek对准的证人遥测系统,以提供高效的训练.
- 使用网络威胁知识图 (CTKG) 进行因果关系和决策增强.
- 实施传感器预算政策,用于成本和延迟决策.
主要成果:
- 在低虚假阳性率 (FPR) 准确度方面,与传统技术相比显著改进.
- 实现了增强的检测时间 (TTD) 和对零日攻击实例的改进校准.
- 提供可追溯的解释,通过防御来源的功能生成的警报.
结论:
- 拟议的框架为先进的网络防御提供了一个强大而可审计的管道.
- 它有效地解决了传统方法在检测新威胁和管理资源方面的局限性.
- 知识图和因果推理的整合增强了威胁的检测和响应.
相关概念视频
Introduction to Learning
923
Learning is the process of acquiring knowledge or skills through practice or experience, leading to long-lasting behavioral changes. This acquisition occurs through interaction with the environment and requires practice or experience. For instance, mastering a skill such as surfing requires considerable practice and experience, highlighting the essential role of repeated interactions with the environment in learning.
In contrast to learned behaviors, unlearned behaviors such as crying, sexual...
In contrast to learned behaviors, unlearned behaviors such as crying, sexual...
923
Reinforcement
816
Positive and negative reinforcement are key concepts in operant conditioning, a learning process where the consequences of a behavior affect the likelihood of that behavior being repeated.
Positive reinforcement occurs when a behavior is followed by the presentation of a rewarding stimulus, increasing the frequency of that behavior. For example:
Positive reinforcement occurs when a behavior is followed by the presentation of a rewarding stimulus, increasing the frequency of that behavior. For example:
816
Avoidance Learning and Learned Helplessness
2.5K
Avoidance learning and learned helplessness are critical concepts in understanding behavioral responses to negative stimuli.
Avoidance learning occurs when an organism learns that a specific behavior can prevent an unpleasant outcome. For example, a student who receives a bad grade may start studying harder to avoid future poor grades. This behavior persists even when the negative outcome is no longer present. Avoidance learning is powerful because it maintains behavior in the absence of the...
Avoidance learning occurs when an organism learns that a specific behavior can prevent an unpleasant outcome. For example, a student who receives a bad grade may start studying harder to avoid future poor grades. This behavior persists even when the negative outcome is no longer present. Avoidance learning is powerful because it maintains behavior in the absence of the...
2.5K
Reinforcement Schedules
447
Positive reinforcement is a powerful method for teaching new behaviors to both animals and humans. B.F. Skinner demonstrated this with his experiments using rats in a Skinner box. When a rat pressed a lever, it received a food pellet. This immediate reward encouraged the rat to repeat the behavior. This method, where a reward follows every instance of the behavior, is known as continuous reinforcement. It is highly effective for establishing new behaviors quickly.
Once a behavior is learned,...
Once a behavior is learned,...
447
Cognitive Learning
997
Cognitive learning is based on purposive behavior, incidental learning, and insight learning.
E. C. Tolman's theory of purposive behavior emphasizes that much behavior is goal-directed. He argued that to understand behavior, we must look at the entire sequence of actions leading to a goal. For instance, high school students study hard, not just due to past reinforcement but also to achieve the goal of getting into a good college.
Tolman introduced the idea that behavior is influenced by...
E. C. Tolman's theory of purposive behavior emphasizes that much behavior is goal-directed. He argued that to understand behavior, we must look at the entire sequence of actions leading to a goal. For instance, high school students study hard, not just due to past reinforcement but also to achieve the goal of getting into a good college.
Tolman introduced the idea that behavior is influenced by...
997
Observational Learning
817
Albert Bandura's observational learning, also known as imitation or modeling, occurs when a person observes and imitates another's behavior. It is a quicker process than operant conditioning. A well-known example is the Bobo doll study, where children who saw an adult acting aggressively towards the doll were more likely to act aggressively when left alone, compared to those who observed a nonaggressive adult. Many psychologists view observational learning as a form of latent learning...
817


