| 面向系统漏洞修复的恶意流量漂移检测方法 |
| Unsupervised real‑time flow drift detection based on entropy of dilichlet distribution |
| |
| DOI: |
| 中文关键词: 电力物联网;漂移检测;恶意流量检测;入侵检测 |
| 英文关键词:power Internet of Things(PIoT); drift detection; malicious traffic detection; intrusion detection |
| 基金项目:国家重点研发计划(2022YFB3104300)资助项目 |
| 作者 | 单位 | | 席泽生 | 1. 国网智能电网研究院有限公司,江苏 南京 210003
2. 中国电力科学研究院有限公司,江苏 南京 210003
3. 南京理工大学 计算机与工程学院,江苏 南京 210014 | | 张波 | 1. 国网智能电网研究院有限公司,江苏 南京 210003
2. 中国电力科学研究院有限公司,江苏 南京 210003 | | 王云帆 | 1. 国网智能电网研究院有限公司,江苏 南京 210003
2. 中国电力科学研究院有限公司,江苏 南京 210003
4. 东南大学 网络空间安全学院,江苏 南京 211189 | | 何川 | 1. 国网智能电网研究院有限公司,江苏 南京 210003
2. 中国电力科学研究院有限公司,江苏 南京 210003
4. 东南大学 网络空间安全学院,江苏 南京 211189 |
|
| 摘要点击次数: 183 |
| 全文下载次数: 40 |
| 中文摘要: |
| 在电力物联网(Power Internet of Things, PIoT)中,系统漏洞是攻击的主要入口,而入侵检测系
统(Intrusion Detection System, IDS)则作为首道防线,负责识别异常行为与潜在威胁。然而,当前
PIoT环境中部署的多数IDS仍基于静态检测模型,难以有效应对快速演化的攻击方式和动态变化
的数据分布。尤其在边缘设备资源受限、系统对实时性要求较高的情况下,现有检测与修复机制
在实用性和部署效率方面面临严峻挑战。因此,构建一种轻量级、低依赖、可在无标签条件下实现
攻击检测与漏洞修复协同工作的安全框架,成为亟需突破的关键研究问题。针对上述问题,文中
提出了一种基于狄利克雷分布熵的无监督实时流量漂移检测方法,通过狄利克雷分布建模恶意流
量检测模型输出概率值的置信度,并计算其熵值作为漂移检测的度量值。此外,采用基于滑动窗
口加权CUSUM型快速检测方法实时监测熵的变化,进而检测数据分布漂移。最后,在公共数据集
上验证了该方法的准确性和实时性,并与其他方法进行了比较。结果表明,文中提出的漂移检测
方法实现了最佳性能。 |
| 英文摘要: |
| In the power Internet of things (PIoT), system vulnerabilities often serve as primary entry
points for cyberattacks, while intrusion detection systems (IDS) act as the first line of defense by identifying abnormal behaviors and potential threats. However, most IDSs currently deployed in PIoT still rely
on static detection models, which are insufficient to cope with rapidly evolving attack patterns and dynamically changing data distributions. Particularly under the constraints of limited edge device resources
and high real-time requirements, existing detection and remediation mechanisms face significant challenges in terms of practicality and deployment efficiency. Therefore, developing a lightweight, low-dependency security framework capable of collaboratively performing attack detection and vulnerability
remediation under label-free conditions has become a critical research issue. To address this challenge,
this paper proposes an unsupervised real-time traffic drift detection method based on Dirichlet entropy.
This approach models the confidence scores of the malicious traffic detection model’s output using a
Dirichlet distribution and computes the entropy as a metric for drift detection. Furthermore, a weighted
CUSUM-based fast detection method with a sliding window is adopted to monitor entropy changes in real
time, enabling effective detection of distributional shifts. Experiments on public datasets demonstrate
that the proposed method achieves superior accuracy and responsiveness compared to other baseline
methods. |
| 查看全文 查看/发表评论 附件 |