Pith. sign in

REVIEW 1 cited by

Enhancing Automata Learning with Statistical Machine Learning: A Network Security Case Study

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2405.11141 v2 pith:MDVVMYCU submitted 2024-05-18 cs.CR cs.SE

classification cs.CRcs.SE
keywords learningautomatadatadetectionintrusionnetworknumericmachines
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Intrusion detection systems are crucial for network security. Verification of these systems is complicated by various factors, including the heterogeneity of network platforms and the continuously changing landscape of cyber threats. In this paper, we use automata learning to derive state machines from network-traffic data with the objective of supporting behavioural verification of intrusion detection systems. The most innovative aspect of our work is addressing the inability to directly apply existing automata learning techniques to network-traffic data due to the numeric nature of such data. Specifically, we use interpretable machine learning (ML) to partition numeric ranges into intervals that strongly correlate with a system's decisions regarding intrusion detection. These intervals are subsequently used to abstract numeric ranges before automata learning. We apply our ML-enhanced automata learning approach to a commercial network intrusion detection system developed by our industry partner, RabbitRun Technologies. Our approach results in an average 67.5% reduction in the number of states and transitions of the learned state machines, while achieving an average 28% improvement in accuracy compared to using expertise-based numeric data abstraction. Furthermore, the resulting state machines help practitioners in verifying system-level security requirements and exploring previously unknown system behaviours through model checking and temporal query checking. We make our implementation and experimental data available online.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. PromptLA: Towards Integrity Verification of Black-box Text-to-Image Diffusion Models

    cs.CV 2024-12 conditional novelty 7.0 of 10

    A training-free integrity verification method for black-box text-to-image diffusion models that detects tampering via KL divergence between feature distributions and selects discriminating prompts with a learning automaton.

Pith tools