RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    보안관제센터 탐지 데이터에 대한 연합학습 적용 및 라벨 불일치 문제 해결 방안 연구 = Federated Learning for Security Operation Centers : Addressing the Label Inconsistency Problem

    한글로보기

    https://www.riss.kr/link?id=T17372363

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    연합학습(Federated Learning, FL)은 정책적 제약으로 인해 직접적인 데이터 공유 가 불가능한 분산 정보 시스템에서 협력적 머신러닝(ML)을 수행하기 위한 핵심 접 근 방식으로 부상하고 있다. 본 연구는 신뢰할 수 있는 ML 기반 의사결정 지원을 위해 이벤트 데이터의 일관된 해석이 필수적인 보안관제센터(SOC) 환경에서, 센서 (예: Snort/Suricata)가 생성하는 구조화된 이벤트 기록인 네트워크 침입탐지시스템 (IDS) 알람 분류를 위한 연합학습을 다룬다. 그러나 조직 간 라벨링 기준의 차이는 빈번하게 의미적 불일치를 초래하여, 연합학습 모델의 정확도와 일반화 성능을 저 해하는 요인이 된다. 본 논문은 원본 데이터의 교환 없이 이러한 문제를 완화하기 위한 두 가지 핵심 기여를 제시한다. 첫째, 키 기반 피처 해싱(Keyed Feature Hashing, KFH)을 제안한다. 이는 키 의존적 난독화 인코딩 기법으로, 모델 역전 (model inversion) 위험을 감소시키면서도 여러 기관에 걸친 이질적인 IDS 알람을 일관되게 벡터화할 수 있게 한다. 둘째, KFH 표현을 활용하여 기관 간 라벨 불일 치로 인해 오분류될 가능성이 높은 알람을 식별하고 제외하는 필터링 메커니즘을 도입한다. 14개 조직에서 수집된 대규모 실제 데이터셋을 이용한 실험 결과, 제안 기법은 99% 이상의 알람 커버리지(alert coverage)를 유지하면서 분류 F1-score를 최대 13.36% 향상시킴을 입증하였다. 이러한 기여는 라벨 불일치가 존재하는 분산 환경에서 연합학습 기반 의사결정 모델의 신뢰성을 크게 강화한다.
    번역하기

    연합학습(Federated Learning, FL)은 정책적 제약으로 인해 직접적인 데이터 공유 가 불가능한 분산 정보 시스템에서 협력적 머신러닝(ML)을 수행하기 위한 핵심 접 근 방식으로 부상하고 있다. 본 ...

    연합학습(Federated Learning, FL)은 정책적 제약으로 인해 직접적인 데이터 공유 가 불가능한 분산 정보 시스템에서 협력적 머신러닝(ML)을 수행하기 위한 핵심 접 근 방식으로 부상하고 있다. 본 연구는 신뢰할 수 있는 ML 기반 의사결정 지원을 위해 이벤트 데이터의 일관된 해석이 필수적인 보안관제센터(SOC) 환경에서, 센서 (예: Snort/Suricata)가 생성하는 구조화된 이벤트 기록인 네트워크 침입탐지시스템 (IDS) 알람 분류를 위한 연합학습을 다룬다. 그러나 조직 간 라벨링 기준의 차이는 빈번하게 의미적 불일치를 초래하여, 연합학습 모델의 정확도와 일반화 성능을 저 해하는 요인이 된다. 본 논문은 원본 데이터의 교환 없이 이러한 문제를 완화하기 위한 두 가지 핵심 기여를 제시한다. 첫째, 키 기반 피처 해싱(Keyed Feature Hashing, KFH)을 제안한다. 이는 키 의존적 난독화 인코딩 기법으로, 모델 역전 (model inversion) 위험을 감소시키면서도 여러 기관에 걸친 이질적인 IDS 알람을 일관되게 벡터화할 수 있게 한다. 둘째, KFH 표현을 활용하여 기관 간 라벨 불일 치로 인해 오분류될 가능성이 높은 알람을 식별하고 제외하는 필터링 메커니즘을 도입한다. 14개 조직에서 수집된 대규모 실제 데이터셋을 이용한 실험 결과, 제안 기법은 99% 이상의 알람 커버리지(alert coverage)를 유지하면서 분류 F1-score를 최대 13.36% 향상시킴을 입증하였다. 이러한 기여는 라벨 불일치가 존재하는 분산 환경에서 연합학습 기반 의사결정 모델의 신뢰성을 크게 강화한다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Federated learning (FL) is emerging as a key approach for collaborative machine learning (ML) in distributed information systems where direct data sharing is infeasible due to policy constraints. In security operations center (SOC) settings, we study FL for the classification of network intrusion detection system (IDS) alerts—structured event records emitted by sensors (e.g., Snort/Suricata)—where consistent interpretation of event data is critical for reliable ML-based decision support. However, differences in labeling criteria across organizations often lead to semantic inconsistencies, undermining the accuracy and generalizability of FL models. This paper presents two key contributions that mitigate this issue without requiring raw data exchange. First, we propose Keyed Feature Hashing (KFH), a key-dependent obfuscated encoding scheme that enables consistent vectorization of heterogeneous IDS alerts across entities while reducing the risk of model inversion. Second, we introduce a filtering mechanism that leverages KFH representations to identify and exclude alerts likely to be misclassified due to inter-entity label discrepancies. Experiments using a large-scale real-world dataset collected from 14 organizations demonstrate that our method improves classification F1-score by up to 13.36% while maintaining over 99% alert coverage. These contributions enhance the trustworthiness of FL-based decision
    models in distributed, label-divergent environments.
    번역하기

    Federated learning (FL) is emerging as a key approach for collaborative machine learning (ML) in distributed information systems where direct data sharing is infeasible due to policy constraints. In security operations center (SOC) settings, we study ...

    Federated learning (FL) is emerging as a key approach for collaborative machine learning (ML) in distributed information systems where direct data sharing is infeasible due to policy constraints. In security operations center (SOC) settings, we study FL for the classification of network intrusion detection system (IDS) alerts—structured event records emitted by sensors (e.g., Snort/Suricata)—where consistent interpretation of event data is critical for reliable ML-based decision support. However, differences in labeling criteria across organizations often lead to semantic inconsistencies, undermining the accuracy and generalizability of FL models. This paper presents two key contributions that mitigate this issue without requiring raw data exchange. First, we propose Keyed Feature Hashing (KFH), a key-dependent obfuscated encoding scheme that enables consistent vectorization of heterogeneous IDS alerts across entities while reducing the risk of model inversion. Second, we introduce a filtering mechanism that leverages KFH representations to identify and exclude alerts likely to be misclassified due to inter-entity label discrepancies. Experiments using a large-scale real-world dataset collected from 14 organizations demonstrate that our method improves classification F1-score by up to 13.36% while maintaining over 99% alert coverage. These contributions enhance the trustworthiness of FL-based decision
    models in distributed, label-divergent environments.

    더보기

    목차 (Table of Contents)

    • I. 서론 1
    • II. 문제 정의 및 연구 동기 4
    • III. 보안관제센터를 위한 적응형 연합학습 9
    • 1. 연합학습 기반 모델 학습 10
    • 2. 필터 생성 12
    • I. 서론 1
    • II. 문제 정의 및 연구 동기 4
    • III. 보안관제센터를 위한 적응형 연합학습 9
    • 1. 연합학습 기반 모델 학습 10
    • 2. 필터 생성 12
    • 3. 필터링 및 테스트 14
    • 4. 평가 지표 14
    • IV. 실험 및 검증 16
    • 1. 실험 데이터셋 및 환경 16
    • 2. 실험 결과 20
    • V. 관련 연구 26
    • VI. 결론 29
    • 참고문헌 31
    • 영문 요약 36
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼