Salvato in:
Dettagli Bibliografici
Autori principali: Zhang, Lili, Zhu, Quanyan, Ray, Herman, Xie, Ying
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:https://arxiv.org/abs/2501.16393
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866915286916005888
author Zhang, Lili
Zhu, Quanyan
Ray, Herman
Xie, Ying
author_facet Zhang, Lili
Zhu, Quanyan
Ray, Herman
Xie, Ying
contents Network threat detection has been challenging due to the complexities of attack activities and the limitation of historical threat data to learn from. To help enhance the existing practices of using analytics, machine learning, and artificial intelligence methods to detect the network threats, we propose an integrated modelling framework, where Knowledge Graph is used to analyze the users' activity patterns, Imbalanced Learning techniques are used to prune and weigh Knowledge Graph, and LLM is used to retrieve and interpret the users' activities from Knowledge Graph. The proposed framework is applied to Agile Threat Detection through Online Sequential Learning. The preliminary results show the improved threat capture rate by 3%-4% and the increased interpretabilities of risk predictions based on the users' activities.
format Preprint
id arxiv_https___arxiv_org_abs_2501_16393
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Improving Network Threat Detection by Knowledge Graph, Large Language Model, and Imbalanced Learning
Zhang, Lili
Zhu, Quanyan
Ray, Herman
Xie, Ying
Machine Learning
Cryptography and Security
Network threat detection has been challenging due to the complexities of attack activities and the limitation of historical threat data to learn from. To help enhance the existing practices of using analytics, machine learning, and artificial intelligence methods to detect the network threats, we propose an integrated modelling framework, where Knowledge Graph is used to analyze the users' activity patterns, Imbalanced Learning techniques are used to prune and weigh Knowledge Graph, and LLM is used to retrieve and interpret the users' activities from Knowledge Graph. The proposed framework is applied to Agile Threat Detection through Online Sequential Learning. The preliminary results show the improved threat capture rate by 3%-4% and the increased interpretabilities of risk predictions based on the users' activities.
title Improving Network Threat Detection by Knowledge Graph, Large Language Model, and Imbalanced Learning
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2501.16393