Automatic Alert Categories Standardization for Heterogeneous Devices with Incomplete Semantic Knowledge Based on LSTM
摘要
In the realm of cybersecurity situational awareness, systems compile alert logs from diverse network monitors. These logs exhibit large-scale dimensions, numerous alert types, and autonomous alert categories. Ensuring precise and efficacious analysis necessitates the standardization and incorporation of these logs into a unified alert type categorization. Conventionally, security experts can manually categorize and standardize alert types by scrutinizing their semantic descriptions. However, this approach is inherently subjective and limited to alerts with comprehensive descriptions already known to the experts. To confront these challenges, we pioneer a groundbreaking method that automates alert type standardization without dependence on semantic information, harnessing solely the inherent attack behavior attributes and attacker-victim ratios extracted from the logs themselves. Specifically, we commence by encapsulating each alert type within a 27-dimensional feature vector, derived from its corresponding alert logs over a defined time frame. Subsequently, we utilize Long Short-Term Memory (LSTM) neural networks to homogenize these alert types. We undertake experiments on online alert logs, achieving an outstanding 92.308% accuracy in automatically categorizing 223 distinct alert types into 12 standardized classifications. These outcomes attest to the significant enhancement in efficiency and precision engendered by our method in alert categorization. Given that the alert logs encompass data from multiple NDR (Network Detection and Response Device) devices, this experimentation further substantiates the robustness of the proposed methodology.