An Ensemble Approach for Suspicious Traffic Detection from High Recall Network Alerts.

Peilin Wu,Jinlei Li,Yan Meng,Haojin Zhu
DOI: https://doi.org/10.1109/BigData47090.2019.9005988
IF: 4.426
2019-01-01
Big Data
Abstract:Web services from large-scale systems are prevalent all over the world. However, these systems are naturally vulnerable and incline to be intruded by adversaries for illegal benefits. To detect anomalous events, previous works focus on inspecting raw system logs by identifying the outliers in workflows or relying on machine learning methods. Though those works successfully identify the anomalies, their models use large training set and process whole system logs. To reduce the quantity of logs that need to be processed, high recall suspicious network alert systems can be applied to preprocess system logs. Only the logs that trigger alerts are retrieved for further usage. Due to the universally usage of network traffic alerts among Security Operations Center, anomalies detection problems could be transformed to classify truly suspicious network traffic alerts from false alerts.
What problem does this paper attempt to address?