Efficient alert aggregation and attack intent inference based on group intelligence algorithm and feature similarity
Online published: 2025-08-20
Copyright
In intrusion detection scenarios, recognizing attack traffic while generating a large number of redundant alerts leads to high false alarm rates and omission of real attacks, which makes it difficult to perform attacker intent inference. To address the above problems, this paper proposes an alert aggregation and attack intent inference method based on group intelligence algorithm with feature similarity, which implements attacker intent inference based on Hidden Markov Model. The method introduces a whale optimization algorithm to compute the weights of the features of different alert types, while adding a dynamic update algorithm to adjust the aggregation time window and compute the feature similarity values of the alerts, and achieves alert aggregation through weighted computation and threshold comparison. Further, random wandering and modularity optimized community detection is introduced to generate probability matrices to identify the attack intent by finding the maximum probability path using Viterbi algorithm. Experimental results show that the method achieves an aggregation rate of 90.81% for tens of thousands of scale alerts, and outperforms similar schemes in terms of attack intent prediction precision rate, recall rate, and F1 value by 65.42%, 94.52%, and 77.32%, respectively.
SUN Yongqing , LI Guorui , GONG Yi , TANG Zifeng , TANG Keyi , SONG Yubo . Efficient alert aggregation and attack intent inference based on group intelligence algorithm and feature similarity[J]. Journal of Cybersecurity, 2025 , 3(3) : 79 -90 . DOI: 10.20172/j.issn.2097-3136.250306
表 1 Brute Force攻击特征权重值Table 1 Feature weight values for Brute Force attack |
| 特征 | 权重值 |
| Fwd IAT Tot | 0.057 |
| Init Fwd Win Byts | 0.261 |
| Flow IAT Max | 0.084 |
| TotLen Fwd Pkts | 0.038 |
| Active Mean | 0.384 |
| Fwd Blk Rate Avg | 0.176 |
表 2 Infiltration攻击特征权重值Table 2 Feature weight values for Infiltration attack |
| 特征 | 权重值 |
| Fwd IAT Mean | 0.141 |
| Pkt Len Var | 0.079 |
| Fwd Pkt Len Std | 0.192 |
| Bwd Pkt Len Mean | 0.258 |
| Fwd PSH Flags | 0.154 |
| Init Fwd Win Byts | 0.176 |
表 3 DoS attacks-GoldenEye攻击特征权重值Table 3 Feature weight values for DoS attacks-GoldenEye attack |
| 特征 | 权重值 |
| Fwd IAT Tot | 0.138 |
| Bwd Pkt Len Max | 0.052 |
| Init Bwd Win Byts | 0.068 |
| Fwd Pkt Len Mean | 0.742 |
表 4 Benign攻击特征权重值Table 4 Feature weight values for Benign attack |
| 特征 | 权重值 |
| Fwd IAT Tot | 0.167 |
| Pkt Len Mean | 0.259 |
| Fwd Header Len | 0.341 |
| Bwd IAT Min | 0.142 |
| Fwd IAT Std | 0.091 |
表 5 不同相似度阈值对警报聚合的影响Table 5 Influence of different similarity thresholds on alarm aggregation |
| 相似度阈值 | 聚合率 | 准确率 | 漏报率 | 误报率 |
| 0.6 | 90.89% | 85.23% | 12.50% | 5.30% |
| 0.7 | 85.34% | 87.15% | 10.20% | 4.80% |
| 0.8 | 80.12% | 88.90% | 8.40% | 4.00% |
| 0.9 | 75.00% | 90.12% | 7.00% | 3.50% |
表 6 不同特征权重配置对警报聚合的影响Table 6 Influence of different feature weight configurations on alarm aggregation |
| 特征权重配置 | 聚合率 | 准确率 | 漏报率 | 误报率 |
| 0.6:0.4 | 90.81% | 86.40% | 11.00% | 6.20% |
| 0.5:0.5 | 89.20% | 87.10% | 9.80% | 5.50% |
| 0.4:0.6 | 85.15% | 88.00% | 8.40% | 5.00% |
表 7 WOA与传统算法性能对比Table 7 Performance comparison between WOA and traditional algorithms |
| 算法 | 聚合率 | 准确率 | 收敛迭代次数 |
| PSO | 84.32% | 82.15% | 58 |
| GA | 82.76% | 80.93% | 62 |
| WOA | 90.81% | 86.40% | 40 |
表 8 实验中每个攻击阶段的数据统计Table 8 Data statistics of each attack stage in the experiment |
| 阶段 | 数据包数量 | 警报数量/警报类型数量 |
| S1 | 249/11 | |
| S2 | ||
| S3 | 593/7 | |
| S4 | 861/35 |
表 9 攻击阶段M=2的实验结果Table 9 Experimental results of the attack stage with M = 2 |
| N | U | M | 精确率 | 召回率 | F1值 |
| 1 936 | 100 | 2 | 80.98% | 83.54% | 82.24% |
| 3 699 | 500 | 2 | 70.02% | 83.36% | 76.11% |
| 5 987 | 1 000 | 2 | 65.58% | 82.96% | 73.26% |
| 8 235 | 1 500 | 2 | 63.43% | 83.92% | 72.25% |
| 10 489 | 2 000 | 2 | 62.91% | 84.79% | 72.23% |
表 10 攻击阶段M=3的实验结果Table 10 Experimental results of the attack stage with M = 3 |
| N | U | M | 精确率 | 召回率 | F1 |
| 100 | 3 | 92.14% | 95.79% | 93.94% | |
| 500 | 3 | 78.97% | 95.77% | 86.56% | |
| 3 | 73.84% | 95.36% | 83.23% | ||
| 3 | 66.83% | 95.82% | 78.74% | ||
| 2000 | 3 | 66.52% | 95.03% | 78.26% |
表 11 攻击阶段M=4的实验结果Table 11 Experimental results of the attack stage with M = 4 |
| N | U | M | 精确率 | 召回率 | F1值 |
| 2 865 | 100 | 4 | 89.95% | 93.41% | 91.64% |
| 5 439 | 500 | 4 | 79.35% | 93.98% | 86.05% |
| 8 725 | 4 | 72.57% | 94.56% | 82.11% | |
| 11 946 | 4 | 67.79% | 95.08% | 79.15% | |
| 15 207 | 2000 | 4 | 65.42% | 94.52% | 77.32% |
表 12 警报聚合多数据集对比Table 12 Comparison of multiple datasets for alarm aggregation |
| 数据集 | 聚合率 | 准确率 | 误报率 |
| CIC-IDS2018 | 90.81% | 86.40% | 6.20% |
| UNSW-NB15 | 88.21% | 84.63% | 7.05% |
| NSL-KDD | 86.05% | 91.78% | 6.11% |
表 13 多数据集攻击意图推理对比Table 13 Comparison of multiple datasets for attack intention inference |
| 数据集 | M | 精确率 | 召回率 | F1值 |
| CIC-IDS2018 | 4 | 65.42% | 94.52% | 77.32% |
| UNSW-NB15 | 4 | 67.87% | 88.84% | 74.38% |
| NSL-KDD | 4 | 59.76% | 93.12% | 77.53% |
| 1 |
ALBASHEER H, MDSIRAJ M, MUBARAKALI A, et al. Cyber-attack prediction based on network intrusion detection systems for alert correlation techniques: a survey[J]. Sensors, 2022, 22 (4): 1494.
|
| 2 |
VAARANDI R, GUERRA-MANZANARES A. Stream clustering guided supervised learning for classifying NIDS alerts[J]. Future Generation Computer Systems, 2024, 155, 231- 244.
|
| 3 |
WANG W, YI P, JIANG J, et al. Transformer-based framework for alert aggregation and attack prediction in a multi-stage attack[J]. Computers & Security, 2024, 136, 103533.
|
| 4 |
GHADERMAZI J, SHAH A, JAJODIA S. A machine learning and optimization framework for efficient alert management in a cybersecurity operations center[J]. Digital Threats: Research and Practice, 2024, 5(2): 1-23.
|
| 5 |
NIKIFOROVA O, ROMANOVS A, ZABINIAKO V, et al. Detecting and identifying insider threats based on advanced clustering methods[J]. IEEE Access, 2024, 12: 30242-30253.
|
| 6 |
BOUZARBENLABIOD L , BENFERHAT S , BOUBANATEBIBEL T. Integrating security operator knowledge and preferences to the alert correlation process[C]//International Conference on Machine & Web Intelligence. IEEE, 2010: 416-420.
|
| 7 |
杨宏宇, 褚润林, 李东博. 一种新的网络安全态势评估方法[J]. 微电子学与计算机, 2015, 32 (1): 29- 34.
YANG H Y, CHU R L, LI D B. A novel network security situation assessment method[J]. Microelectronics & Computer, 2015, 32 (1): 29- 34.
|
| 8 |
吴琨, 白中英. 集对分析的可信网络安全态势评估与预测[J]. 哈尔滨工业大学学报, 2012, 44 (3): 112- 118.
WU K, BAI Z Y. Trusted network security situational awareness and forecast based on SPA[J]. Journal of Harbin Institute of Technology, 2012, 44 (3): 112- 118.
|
| 9 |
NING P, CUI Y, REEVES D S. Constructing attack scenarios through correlation of intrusion alerts[C]//Proceedings of the 9th ACM Conference on Computer and Communications Security. ACM, 2002: 245-254.
|
| 10 |
LIN Z, LI S, MA Y . Real-time intrusion alert correlation system based on prerequisites and consequence[C]//International Conference on Wireless Communications Networking & Mobile Computing. IEEE, 2010: 1-5.
|
| 11 |
JU A, GUO Y, YE Z, et al. Hetemsd: A big data analytics framework for targeted cyber-attacks detection using heterogeneous multisource data[J]. Security and Communication Networks, 2019(1): 5483918.
|
| 12 |
XIAN X, WU T, LIU Y, et al. Towards link inference attack against network structure perturbation[J]. Knowledge-Based Systems, 2021, 218, 106674.
|
| 13 |
KUWANO M, OKUMA M, OKADA S, et al. The attacker might also do next: ATT&CK behavior forecasting by attacker-based collaborative filtering and graph databases[J]. Journal of Information Processing, 2023, 31, 802- 811.
|
| 14 |
LI Y, FAN W, LUO R. Machine Learning-based Approach for Enhancing Multi-step Attack Prediction[C]//2023 24st Asia Pacific Network Operations and Management Symposium (APNOMS). IEEE, 2023: 48-53
|
| 15 |
YU T, XIN Y, ZHU H, et al. Network penetration intrusion prediction based on attention seq2seq model[J]. Security and Communication Networks, 2022(1): 6012232
|
| 16 |
LANDAUER M, SKOPIK F, WURZENBERGER M. Introducing a new alert data set for multi-step attack analysis[J]. arXiv preprint, arXiv: 2308. 12627, 2023
|
| 17 |
孙澄, 胡浩, 杨英杰, 等. 基于网络防御知识图谱的 0day攻击路径预测方法[J]. 网络与信息安全学报, 2022, 8(1): 151-166.
SUN C, HU H, YANG Y J, et al. 0day attack path prediction method based on network defense knowledge graph[J].Chinese Journal of Network and Information Security, 2022, 8(1): 151-166.
|
| 18 |
谢峥, 路广平, 付安民. 一种可扩展的实时多步攻击场景重构方法[J]. 信息安全研究, 2023, 9 (12): 1173- 1179.
XIE Z, LU G P, FU A M. An extensible real-time multi-step attack scenario reconstruction method[J]. Journal of Information Security Research, 2023, 9 (12): 1173- 1179.
|
| 19 |
HAO F, WANG Z, SHI M, et al. Inferring attack paths in networks with periodic topology changes[C]//2022 IEEE Smartworld, Ubiquitous Intelligence & Computing, Scalable Computing & Communications, Digital Twin, Privacy Computing, Metaverse, Autonomous & Trusted Vehicles (SmartWorld/UIC/ScalCom/DigitalTwin/PriComp/Meta). IEEE, 2022: 724-731.
|
| 20 |
WERNER G, YANG S J, MCCONKY K. Near real-time intrusion alert aggregation using concept-based learning[C]//Proceedings of the 18th ACM International Conference on Computing Frontiers. ACM, 2021: 152-160.
|
| 21 |
孟泽儒. 网络攻击预测及防御方案生成系统研究与实现 [D]. 南京: 南京邮电大学, 2023.
MENG Z R. Research and implementation of network attack prediction and defense scheme generation system[D]. Nanjing: Nanjing University of Posts and Telecommunications, 2023.
|
| 22 |
DASS S, DATTA P, NAMIN A S. Attack prediction using hidden markov model[C]//2021 IEEE 45th Annual Computers, Software, and Applications Conference ( COMPSAC) . IEEE, 2021: 1695-1702.
|
| 23 |
DATTA P, LODINGER N, NAMIN A S, et al. Cyber-attack consequence prediction[J]. arXiv preprint, arXiv: 2012. 00648, 2020.
|
| 24 |
BI J, XU K, YUAN H, et al. A hybrid deep learning method for network attack prediction[C]//2022 IEEE International Conference on Systems, Man, and Cybernetics (SMC). IEEE, 2022: 544-549.
|
| 25 |
LATIF S, ZOU Z, IDREES Z, et al. A novel attack detection scheme for the industrial internet of things using a lightweight random neural network[J]. IEEE Access, 2020, 8: 89337-89350.
|
| 26 |
BEN FREDJ O, MIHOUB A, KRICHEN M, et al. CyberSecurity attack prediction: A deep learning approach[C]//13th International Conference on Security of Information and Networks. 2020: 1-6.
|
| 27 |
DALAL S, MANOHARAN P, LILHORE U K, et al. Extremely boosted neural network for more accurate multi-stage cyber attack prediction in cloud computing environment[J]. Journal of Cloud Computing, 2023, 12(1): 14.
|
| 28 |
ABDELKHALEK M, GOVINDARASU M. ML-based alert correlation algorithms for DER cyber situational awareness[C]//2024 IEEE Power & Energy Society Innovative Smart Grid Technologies Conference . IEEE, 2024: 1-5
|
| 29 |
BAHADORIPOUR S, KARIMIPOUR H, JAHROMI A N, et al. An explainable multi-modal model for advanced cyber-attack detection in industrial control systems[J]. Internet of Things, 2024, 25: 101092.
|
| 30 |
SOURI A, NOROUZI M, ALSENANI Y. A new cloud-based cyber-attack detection architecture for hyper-automation process in industrial internet of things[J]. Cluster Computing, 2024, 27(3): 3639-3655.
|
| 31 |
ALDALLAL A. Toward efficient intrusion detection system using hybrid deep learning approach[J]. Symmetry, 2022, 14(9): 1916.
|
| 32 |
SETH S, CHAHAL K K, SINGH G. A novel ensemble framework for an intelligent intrusion detection system[J]. IEEE Access, 2021, 9: 138451-138467
|
| 33 |
MÉZEŠOVÁ T, SOKOL P, BAJTOŠ T. Evaluation of attackers’ skill levels in multi-stage attacks[J]. Information, 2020, 11(11): 537.
|
| 34 |
PIVARNÍKOVÁ M, SOKOL P, BAJTOŠT. Early-stage detection of cyber attacks[J]. Information, 2020, 11( 12), 560.
|
| 35 |
LANDAUER M, SKOPIK F, WURZENBERGER M, et al. Dealing with security alert flooding: Using machine learning for domain-independent alert aggregation[J]. ACM Transactions on Privacy and Security, 2022, 25(3): 1-36.
|
/
| 〈 |
|
〉 |