Learning device, learning method, and learning program
By clustering and sampling communication feature amounts from over-detection alerts in anomaly detection systems, the proposed method stabilizes the feedback process, reducing learning time and maintaining accuracy in anomaly detection.
Patent Information
- Application Number
- JP2024528224
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-06-23
- Publication Date
- 2025-06-18
- Estimated Expiration
- 2042-06-23
AI Technical Summary
Existing anomaly detection systems using unsupervised machine learning face instability and overlearning issues when performing false positive feedback, leading to prolonged learning times and decreased operational stability.
The system includes an acquisition unit for gathering communication feature amounts, a clustering unit for grouping similar alerts, a sampling unit for identifying periodic patterns, and a learning unit for performing targeted feedback using sampled alerts, thereby stabilizing the anomaly detection process.
This approach allows for the selection of over-detection alerts for feedback that maintains the stability of the anomaly detection system, reducing learning time while preserving accuracy.
Smart Images

Figure 0007694830000001 
Figure 0007694830000002 
Figure 0007694830000003
Abstract
Description
Technical Field
[0001] The present invention relates to a learning device, a learning method, and a learning program.
Background Art
[0002] Anomaly detection technology using unsupervised machine learning is expected to promote the social introduction of the technology because it can detect new types of cyberattacks with high accuracy. Here, in an anomaly detector using unsupervised machine learning, an alert (false positive alert) that is actually normal communication but is detected as abnormal communication may occur. This false positive alert complicates the investigation of the alert and hinders the operation of the anomaly detector. Therefore, in order to reduce false positives of the anomaly detector, it is necessary to perform additional learning (false positive feedback) that the communication targeted by the false positive alert is actually normal communication.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, if false positive feedback is performed using a large number of false positive alerts, the learning time of the anomaly detector may become long, or overlearning may occur, etc., and the operation of the anomaly detector may become unstable. Therefore, it is important to select false positive alerts used for false positive feedback so that the operation of the anomaly detector does not become unstable. However, in the prior art, selection of false positive alerts used for false positive feedback so that the operation of the anomaly detector does not become unstable has not been studied.
[0005] Therefore, an object of the present invention is to solve the above-described problems and select an over-detection alert used for over-detection feedback so that the operation of the anomaly detector does not become unstable.
Means for Solving the Problems
[0006] To solve the above-described problems, the present invention includes an acquisition unit that acquires communication feature amounts of over-detected communications in an anomaly detector that detects communication anomalies, a clustering unit that clusters the acquired communication feature amounts into a plurality of clusters, and for each of the clusters, sorts the communication feature amounts belonging to the cluster in time series, identifies the period of the sorted communication feature amounts, a sampling unit that samples the communication feature amounts at the identified period, and a learning unit that performs additional learning for over-detection feedback on the anomaly detector using the communication feature amounts sampled from each of the clusters.
Effects of the Invention
[0007] According to the present invention, it is possible to select an over-detection alert used for over-detection feedback so that the operation of the anomaly detector does not become unstable.
Brief Description of the Drawings
[0008]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
[0009] Hereinafter, embodiments (embodiments) for carrying out the present invention will be described with reference to the drawings. The present invention is not limited to the embodiments described below.
[0010] [Overview] First, the overview of the learning device of the present embodiment will be described with reference to FIG. 1. The learning device performs over-detection feedback of an anomaly detector (a device that detects communication anomalies based on a machine learning model pre-trained).
[0011] First, the learning device acquires an over-detection alert group of the anomaly detector. Then, the learning device clusters similar over-detection alert groups. For example, when the learning device acquires 3000 over-detection alert groups, it clusters them into cluster A (300) and cluster B (2700) based on the mixture Gaussian model.
[0012] Next, the learning device sorts the over-detection alert groups for each cluster in time series and identifies the periodicity of the over-detection alerts. Then, the learning device samples the over-detection alerts for each cluster in the identified cycle units.
[0013] For example, the learning device samples 100 over-detection alerts from cluster A and 100 over-detection alerts from cluster B. Then, the learning device performs learning for over-detection feedback of the anomaly detector using the sampled over-detection alert groups.
[0014] In this way, the learning device clusters the over-detection alert group, samples the over-detection alerts based on the periodicity of the over-detection alerts in each cluster, and performs over-detection feedback. As a result, the learning device can perform over-detection feedback on the anomaly detector using comprehensive and unbiased over-detection alerts. Consequently, the learning device can perform over-detection feedback in a short time without degrading the accuracy of the anomaly detector.
[0015] [Configuration Example] Next, a configuration example of the learning device 10 will be described with reference to FIG. 2. The learning device 10 includes an input / output unit 11, a storage unit 12, and a control unit 13.
[0016] [Input / Output Unit] The input / output unit 11 manages the interface when the learning device 10 receives or outputs various types of information. For example, the input / output unit 11 receives inputs of over-detection alerts, communication feature amounts associated with the over-detection alerts, and related information of the communication feature amounts (e.g., ID of the communication feature amount, reception time, etc.) from an external database. Further, the input / output unit 11 outputs the processing result by the control unit 13. For example, the input / output unit 11 outputs the number of communication feature amounts used for over-detection feedback in the control unit 13, the ID of the communication feature amount, etc.
[0017] [Storage Unit] The storage unit 12 stores various types of information and programs used when the control unit 13 operates, and various types of information obtained as a result of the operation of the control unit 13. Here, the storage unit 12 is, for example, a semiconductor memory element such as a RAM (Random Access Memory), a flash memory, or a storage device such as a hard disk, an optical disk, etc.
[0018] The storage unit 12 stores, for example, over-detection alerts input via the input / output unit 11, communication feature amounts associated with the over-detection alerts, and related information of the communication feature amounts (collectively referred to as over-detection alert information). The storage unit 12 also stores parameters of a machine learning model used by an anomaly detector targeted for over-detection feedback. This machine learning model is, for example, a model that determines whether an input communication is abnormal and outputs a determination result. The parameters of the machine learning model are updated when the control unit 13 executes learning for over-detection feedback.
[0019] [Control Unit] The control unit 13 controls the entire learning device 10. The control unit 13 includes an acquisition unit 131, a clustering unit 132, a sampling unit 133, a learning unit 134, and an output processing unit 135. The functions of each part of the control unit 13 are realized by a CPU installed in the learning device 10 executing a program stored in the storage unit 12.
[0020] [Acquisition Unit] The acquisition unit 131 acquires an over-detection alert group of an anomaly detector. For example, the acquisition unit 131 acquires an over-detection alert group issued from the same device (anomaly detector) from an external database. Identification of the device uses, for example, the source IP address or source MAC address of the over-detection alert.
[0021] Also, the acquisition unit 131 acquires from the database a communication feature amount associated with the over-detection alert and related information of the communication feature amount (for example, an ID of the communication feature amount, reception time, etc.). The above communication feature amount is a feature amount of traffic communication data targeted by the over-detection alert.
[0022] This communication feature amount includes, for example, the feature amounts shown in FIG. 3. That is, the communication feature amount includes feature amounts such as a communication session duration, a total number of bytes in the forward direction, a total number of packets in the forward direction, an average packet size in the forward direction, a total number of bytes in the reverse direction, a total number of packets in the reverse direction, an average packet size in the reverse direction, a session destination port number, and a determination score by the anomaly detector.
[0023] [Clustering Unit] Return to the description of FIG. 2. The clustering unit 132 clusters communication feature amounts associated with the over-detection alerts acquired by the acquisition unit 131 into a plurality of clusters.
[0024] For example, the clustering unit 132 uses a mixture Gaussian model for the communication feature amounts acquired by the acquisition unit 131 to cluster the communication feature amounts such that similar communication feature amounts belong to the same cluster.
[0025] At this time, for example, the clustering unit 132 first clusters to generate 1 to 10 clusters in order to determine the number of clusters. Then, the clustering unit 132 determines the best number of clusters from among the numbers of 1 to 10 clusters based on the Bayesian information criterion. Note that the type of variance, which is a parameter of the mixture Gaussian model described above, is the same type of variance for each cluster.
[0026] Further, the method of clustering is not limited to the method using the mixture Gaussian model described above as long as the data (communication feature amounts) belonging to each cluster are similar to each other and the data within the cluster are not biased as much as possible.
[0027] [Sampling Unit] The sampling unit 133 samples communication feature amounts from each cluster. For example, the sampling unit 133 sorts the communication feature amount groups belonging to the cluster for each cluster in time series. Then, the sampling unit 133 specifies the period of the communication feature amount group belonging to the cluster for each cluster, and samples the communication feature amounts at the specified period. Note that when the sampling unit 133 cannot specify the period of the communication feature amount group belonging to the cluster, the sampling unit 133 randomly samples communication feature amounts from the cluster.
[0028] Specifically, the sampling unit 133 acquires the data (communication feature amounts) belonging to each cluster and their related information for each cluster. Then, based on the reception time indicated in the acquired related information, the sampling unit 133 sorts the communication feature amounts belonging to each cluster in time series.
[0029] Next, the sampling unit 133 calculates the autocorrelation coefficient from the sorted communication feature amounts within the cluster. Note that the lag, which is a parameter of the autocorrelation coefficient, ranges from 1 to the number of data belonging to the cluster. Then, the sampling unit 133 specifies, as the period (number of periodic data) of the data of the cluster, the lag among the above lags at which the autocorrelation coefficient becomes the maximum value. After that, the sampling unit 133 samples the communication feature amounts at the specified period from the sorted communication feature amounts within the cluster. The sampling unit 133 executes the above processing for each cluster.
[0030] For example, the sampling unit 133 receives an input of the sampling number N for each cluster from the user of the learning device 10. Then, for each cluster, the sampling unit 133 samples the communication feature amounts at the above period (number of periodic data) in order from the communication feature amounts at the oldest time until the sampling number N is satisfied. Then, the sampling unit 133 records the IDs of the sampled communication feature amounts in the learning list.
[0031] Also, when the maximum value of the autocorrelation coefficient of the communication feature amounts within the cluster does not reach a predetermined threshold value, the sampling unit 133 determines that the period of the communication feature amounts of the cluster cannot be specified (there is no periodicity). Then, the sampling unit 133 randomly samples N data communication feature amounts from the cluster. Then, the sampling unit 133 records the IDs of the randomly sampled communication feature amounts in the learning list.
[0032] The learning unit 134 performs learning for the over-detection feedback of the anomaly detector using the communication feature amounts sampled by the sampling unit 133.
[0033] For example, the learning unit 134 acquires communication feature amounts associated with over-detection alerts from the storage unit 12 based on the IDs of the communication feature amounts shown in the above learning list. Then, the learning unit 134 uses the acquired communication feature amounts as learning data for normal communication to perform additional learning on the machine learning model used by the anomaly detector and updates the parameters of the machine learning model.
[0034] The output processing unit 135 outputs the processing result by the control unit 13 via the input / output unit 11. For example, the output processing unit 135 outputs the number of communication feature amounts used for the over-detection feedback of the anomaly detector, the IDs of the communication feature amounts, the time required for the over-detection feedback, and the like.
[0035] According to such a learning device 10, it is possible to perform over-detection feedback in a short time without degrading the accuracy of the anomaly detector. As a result, the learning device 10 can stably operate the anomaly detector.
[0036] [Example of processing procedure] Next, an example of the processing procedure of the learning device 10 will be described with reference to FIG. 4. For example, the learning device 10 receives an input of an over-detection alert ID and the required number of data N (the number of sampling data per cluster) (S1). Then, the acquisition unit 131 acquires communication feature amounts and related information (for example, the reception time of the communication feature amounts) associated with the over-detection alert ID received in S1 from the database (S2). Then, the clustering unit 132 clusters the communication feature amounts acquired in S2 (S3).
[0037] Thereafter, the sampling unit 133 executes the following processing of S4 to S9 for each cluster generated by the clustering in S3. First, the sampling unit 133 determines whether the number of data (communication feature amounts) in the cluster generated in S3 exceeds N (S4). If it is determined that the number exceeds N (Yes in S4), the communication feature amounts in the cluster are sorted by the reception time (S6).
[0038] After S6, the sampling unit 133 determines whether there is periodicity in the communication feature amounts within the cluster (S7). If it is determined that there is periodicity (Yes in S7), the number of cycle data satisfying the above N is added to the learning list (S9). For example, when the sampling unit 133 identifies the cycle of the sorted communication feature amount group within the cluster, the sampling unit 133 samples the communication feature amounts for each identified cycle. Then, the sampling unit 133 adds the IDs of the sampled communication feature amounts to the learning list.
[0039] Also, in S4, when the sampling unit 133 determines that the number of data in the cluster generated in S3 does not exceed N (No in S4), the sampling unit 133 adds the IDs of all the communication feature amounts of the cluster to the learning list (S5: add all to the learning list). Then, the process moves to the processing of the next cluster.
[0040] Also, in S7, when the sampling unit 133 determines that there is no periodicity in the communication feature amounts within the cluster (No in S7), the sampling unit 133 adds the IDs of the communication feature amounts randomly sampled from the communication feature amounts of the cluster to the learning list (S8: add to the learning list by random sampling). Then, the process moves to the processing of the next cluster.
[0041] After the sampling unit 133 executes the processes of S4 to S9 for all the clusters, the learning unit 134 performs over-detection feedback on the anomaly detector using the communication feature amounts with the IDs described in the learning list (S10). For example, the learning unit 134 performs additional learning for over-detection feedback on the machine learning model used by the anomaly detector using the communication feature amounts with the IDs described in the learning list. Then, the output processing unit 135 outputs the IDs, the number, etc. of the communication feature amounts used for the over-detection feedback (S11).
[0042] By the learning device 10 executing the above processes, it is possible to perform over-detection feedback in a short time without degrading the accuracy of the anomaly detector. As a result, the learning device 10 can stably operate the anomaly detector.
[0043] Note that the learning device 10 only samples the communication feature amounts used for over-detection feedback, and the over-detection feedback using the communication feature amounts may be executed by another device. In this case, the learning device 10 outputs the sampled communication feature amounts to the device. Then, the device performs over-detection feedback using the communication feature amounts output from the learning device 10.
[0044] Further, the learning device 10 may further include a detection unit that detects an abnormality in the input communication using the machine learning model after over-detection feedback.
[0045] [Evaluation Results] Next, the results of the evaluation experiment of the accuracy and learning time of the anomaly detector (machine learning model) that performed over-detection feedback by the learning device 10 of the present embodiment will be described.
[0046] [Experiment Conditions] The experiment conditions are as follows. · The initial learning of the anomaly detector is performed in a state where it has been sufficiently learned. · New communication is input to the anomaly detector to generate an over-detection alert. Note that the new communication to be input is communication of two types of communication protocols. · The comparative example is an anomaly detector that performed over-detection feedback using over-detection alerts (2000 pieces). · The learning device 10 of the present embodiment performed over-detection feedback of the anomaly detector using over-detection alerts (600 pieces) sampled from the above over-detection alerts (2000 pieces). · The evaluation data is data of normal communication (350 pieces) and data of abnormal communication (350 pieces). Using this evaluation data, the accuracy (AUC score) and learning time of each of the anomaly detector of the comparative example and the anomaly detector that performed over-detection feedback by the learning device 10 of the present embodiment were evaluated. · The machine used for the anomaly detector is a terminal on VMware Esxi, with CPU: 16 vCPU and memory: 32 GB.
[0047] The results of the AUC of the anomaly detector in the comparative example and the anomaly detector that performed over-detection feedback with the learning device 10 of the present embodiment are as shown in FIG. 5.
[0048] As shown in FIG. 6, the anomaly detector that performed over-detection feedback with the learning device 10 of the present embodiment had an accuracy (AUC score) 0.011 higher than that of the anomaly detector in the comparative example. Also, according to the learning device 10 of the present embodiment, it was confirmed that the time required for over-detection feedback (learning time) was shortened by 7 minutes and 54 seconds compared to the comparative example. That is, according to the learning device 10 of the present embodiment, it was confirmed that over-detection feedback can be performed at high speed without degrading the accuracy of the anomaly detector.
[0049] [System configuration, etc.] Also, each component of each part shown in the figure is a functional concept, and it is not necessarily physically configured as shown in the figure. That is, the specific form of the distribution and integration of each device is not limited to that shown in the figure, and all or part of it can be functionally or physically distributed and integrated in any unit according to various loads, usage situations, etc. Furthermore, each processing function performed by each device can be realized in whole or in any part by a CPU and a program executed by the CPU, or can be realized as hardware by wired logic.
[0050] Also, among the processes described in the above-described embodiment, all or part of the processes described as being automatically performed can be manually performed, or all or part of the processes described as being manually performed can be automatically performed by a known method. In addition, the processing procedures, control procedures, specific names, and information including various data and parameters shown in the above documents and drawings can be arbitrarily changed unless otherwise specified.
[0051] [Program] The above-described learning device 10 can be implemented by installing a program (learning program) as package software or online software on a desired computer. For example, by causing the information processing device to execute the above program, the information processing device can function as the learning device 10. The information processing device mentioned here includes mobile communication terminals such as smartphones, mobile phones, and PHS (Personal Handyphone System), and further includes terminals such as PDAs (Personal Digital Assistants).
[0052] FIG. 7 is a diagram showing an example of a computer that executes a learning program. The computer 1000 has, for example, a memory 1010 and a CPU 1020. The computer 1000 also has a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.
[0053] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM (Random Access Memory) 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to the hard disk drive 1090. The disk drive interface 1040 is connected to the disk drive 1100. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1100. The serial port interface 1050 is connected to, for example, a mouse 1110 and a keyboard 1120. The video adapter 1060 is connected to, for example, a display 1130.
[0054] The hard disk drive 1090 stores, for example, an OS 1091, application programs 1092, program modules 1093, and program data 1094. That is, the programs that define the respective processes executed by the learning device 10 described above are implemented as program modules 1093 in which computer-executable code is described. The program modules 1093 are stored, for example, in the hard disk drive 1090. For example, program modules 1093 for executing processes similar to the functional configuration in the learning device 10 are stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced by an SSD (Solid State Drive).
[0055] In addition, the data used in the processes of the above-described embodiments is stored as program data 1094, for example, in the memory 1010 or the hard disk drive 1090. Then, the CPU 1020 reads out the program modules 1093 and program data 1094 stored in the memory 1010 or the hard disk drive 1090 to the RAM 1012 and executes them as necessary.
[0056] Note that the program modules 1093 and program data 1094 are not limited to being stored in the hard disk drive 1090, and may be stored, for example, in a removable storage medium and read by the CPU 1020 via a disk drive 1100 or the like. Alternatively, the program modules 1093 and program data 1094 may be stored in another computer connected via a network (LAN (Local Area Network), WAN (Wide Area Network), etc.). Then, the program modules 1093 and program data 1094 may be read by the CPU 1020 from another computer via the network interface 1070.
Description of Reference Numerals
[0057] 10 Learning device 11 Input / output unit 12 Memory unit 13 Control unit 131 Acquisition unit 132 Clustering unit 133 Sampling unit 134 Learning unit 135 Output processing unit
Claims
1. An acquisition unit that acquires a communication feature amount of over-detected communication in an abnormality detector that detects communication abnormalities; A clustering unit that clusters the acquired communication feature amounts into a plurality of clusters; For each of the clusters, sort the communication feature amounts belonging to the cluster in time series, identify the period of the sorted communication feature amounts, and sample the communication feature amounts at the identified period; a sampling unit; A learning unit that performs additional learning for over-detection feedback on the abnormality detector using the communication feature amounts sampled from each of the clusters; A learning device, characterized by comprising:
2. The clustering unit: Clustering the communication feature amounts into a plurality of clusters using a Gaussian mixture model; The learning device according to claim 1, characterized by:
3. The sampling unit: When the period of the communication feature amounts belonging to the cluster cannot be identified, randomly sample the communication feature amounts from the communication feature amounts belonging to the cluster; The learning device according to claim 1, characterized by:
4. The sampling unit: Calculate the autocorrelation coefficient of each of the sorted communication feature amounts, and identify the period of the communication feature amounts based on the calculated autocorrelation coefficient; The learning device according to claim 1, characterized by:
5. A detection unit that performs abnormality detection of input communication using the abnormality detector after additional learning; The learning device according to claim 1, further characterized by comprising:
6. A learning method executed by a learning device, comprising: A step of acquiring a communication feature amount of over-detected communication in an abnormality detector that detects communication abnormalities; A step of clustering the obtained communication feature amounts into a plurality of clusters; For each of the clusters, sorting the communication feature amounts belonging to the cluster in time series, specifying the period of the sorted communication feature amounts, and sampling the communication feature amounts at the specified period; A step of performing additional learning for over-detection feedback on the anomaly detector using the communication feature amounts sampled from each of the clusters A learning method characterized by executing the above steps.
7. A step of obtaining the communication feature amounts of communications over-detected in an anomaly detector for detecting communication anomalies; A step of clustering the obtained communication feature amounts into a plurality of clusters; For each of the clusters, sorting the communication feature amounts belonging to the cluster in time series, specifying the period of the sorted communication feature amounts, and sampling the communication feature amounts at the specified period; A step of performing additional learning for over-detection feedback on the anomaly detector using the communication feature amounts sampled from each of the clusters A learning program for causing a computer to execute the above steps.
Citation Information
Patent Citations
Attack detection and analysis device and attack detection method
JP2019009549A
Evaluation device and evaluation method
JP2019220866A
Program, method for creating learned model, information processing method and information processing device
JP2021140739A
Infection spread attack detection device, attack origin specification method, and program
WO2020027250A1