Enhancing Decision-Making of Network Intrusion Analysis Assisted by Explainable AI for Real-Time Security Monitoring

Hyun-Woo Lee, Taewoong Kwon, Jun Lee, Jungsuk Song · 2024

Nowadays, Artificial Intelligence (AI) and Machine Learning (ML) are being used as critical technologies regardless of fields. For network security monitoring, AI/ML techniques also broadly adopted to detect various threats from enormous network traffic. It definitely can enable us to make quicker and more accurate threats detection; however, since AI systems are often operated as black boxes, it is hard to understand the cause of detection without additional analysis. To solve these issues, there have been several attempts using explainable-AI (XAI) techniques to interpret decision processes of AI. Nevertheless, it still has limitations especially in terms of response at real-world Security Operations Centers (SOCs), because it only focuses on revealing an importance of pre-defined features. This paper proposes a practical and security monitoring-response friendly XAI framework, which improves rapid and accurate decision-making by human agents of SOCs. Particularly, the framework provides an intuitive evidence of cyber attacks or anomalies through four steps as follows: 1)extracting semantic features, 2)scoring threats importance, 3)ranking risk influences and 4)visualizing decision evidences. For evaluation purposes, we work with a dataset consisting of real-world network traffic and annotated threats factors by security monitoring experts. Furthermore, experimental results demonstrate the effectiveness of our proposed framework in terms of a decision-making support for real-time security monitoring.

Read the paper · More papers on PaperTik