CDSTAEP: Cross-Domain Spatial-Temporal Association Learning for Abnormal Events Prediction
-
Published:2023-03-13
Issue:6
Volume:13
Page:3655
-
ISSN:2076-3417
-
Container-title:Applied Sciences
-
language:en
-
Short-container-title:Applied Sciences
Author:
Gao Mingcheng12ORCID, Wang Ruiheng12ORCID, Zhu Hongliang12, Xin Yang12
Affiliation:
1. Disaster Recovery and Data Security Center, School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100876, China 2. National Engineering Research Center of Disaster Backup and Recovery, Beijing 100876, China
Abstract
Predicting network abnormal events and behavior can enhance security situation awareness and the ability to infer attack intentions. Most of the existing abnormal event prediction methods usually rely on the temporal relationship features between events and the spatial relationship features between hosts. However, the existing spatio-temporal anomaly event prediction methods do not fully consider the spatial relationship between events and the cross-domain environment of the behavior, resulting in poor performance in practical applications. In addition, the existing methods are mostly based on Euclidean space and hyperbolic space in terms of feature space relationship representation and do not fully consider the complexity of the relationship structure of anomalous events. In this paper, we propose a cross-domain spatio-temporal abnormal events prediction method, referred to as CDSTAEP. This method divides the local event sequence based on the temporal behavior sequence of entities and realizes the graphical representation of the multi-domain event correlation relationship. In the mixed-curvature space, we realize the representation learning of the correlation relationship of complex events and combine the event mixed-curvature vector representation and attention-based long short-term memory (LSTM-ATT) to capture the spatial and temporal correlation characteristics of cross-domain events, and finally realize the prediction. In this paper the proposed CDSTAEP is verified with the live network data set collected by a national key research and development plan. The results demonstrate that CDSTAEP can retain more spatial relationship features between events, the area under roc curve (AUC) score is better than the result of single-space representation and is 4.53% and 6.699% higher than the baseline models such as LSTM and LSTM-ATT.
Funder
National Key R&D Program of China under Grant
Subject
Fluid Flow and Transfer Processes,Computer Science Applications,Process Chemistry and Technology,General Engineering,Instrumentation,General Materials Science
Reference47 articles.
1. Liu, Y., Zhang, J., Sabari, A., Liu, M., Karir, M., and Baily, M. (2015, January 4). Predicting cyber security incidents using feature-based characterization of networklevel malicious activities. Proceedings of the 2015 ACM International Workshop on International Workshop on Security and Privacy Analytics, San Antonio, TX, USA. 2. Survey of attack projection, prediction, and forecasting in cyber security;Husak;IEEE Commun. Surv. Tuts.,2019 3. Soska, K., and Christin, N. (2014, January 20–22). Automatically detecting vulnerable websites before they turn malicious. Proceedings of the 23rd USENIX Security Symposium, San Diego, CA, USA. 4. Xu, K., Wang, F., and Gu, L. (2011, January 10–15). Network-aware behavior clustering of internet end hosts. Proceedings of the 2011 Proceedings IEEE INFOCOM, Shanghai, China. 5. Chen, Y., Huang, Z., and Lai, Y. (2015). Spatiotemporal patterns and predictability of cyberattacks. PLoS ONE, 10.
|
|