TY - GEN
T1 - A Quantitative Approach for Threat Assessment from Heterogeneous Web Security Logs
AU - Feng, Wenying
AU - Luo, Cui
AU - Zhu, Ze
AU - Xiang, Xiayu
AU - Zhou, Ke
AU - Gu, Zhaoquan
N1 - Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd. 2027.
PY - 2027
Y1 - 2027
N2 - Intrusion detection systems (IDS) and web application firewalls (WAF) generate overwhelming volumes of alerts, yet lack fine-grained threat assessment capabilities to identify valuable alert clues or high-risk threat events from them. Regarding this problem, we propose a Regression-based fine-grained Threat Assessment Framework called RegTAF for evaluating and analyzing threats in multi-source Web security logs. RegTAF extracts threat entities (e.g., security events and malicious IPs) and characterizes them along multiple dimensions. To overcome label scarcity and severe class imbalance in security logs, we employ unsupervised representation learning to enhance feature discriminability. A regression model is then trained to output the assessment of threat severity, enabling precise risk quantification for security events. Through ablation studies and comparative experiments across multiple regression algorithms, we validate the effectiveness of RegTAF, identify the key threat dimensions governing severity assessment, and provide complexity analysis with different regression algorithms. By implementing RegTAF, high-threat or potentially harmful threat entities can be selected based on fine-grained threat severity, thereby improving the efficiency of web attack detection analysis.
AB - Intrusion detection systems (IDS) and web application firewalls (WAF) generate overwhelming volumes of alerts, yet lack fine-grained threat assessment capabilities to identify valuable alert clues or high-risk threat events from them. Regarding this problem, we propose a Regression-based fine-grained Threat Assessment Framework called RegTAF for evaluating and analyzing threats in multi-source Web security logs. RegTAF extracts threat entities (e.g., security events and malicious IPs) and characterizes them along multiple dimensions. To overcome label scarcity and severe class imbalance in security logs, we employ unsupervised representation learning to enhance feature discriminability. A regression model is then trained to output the assessment of threat severity, enabling precise risk quantification for security events. Through ablation studies and comparative experiments across multiple regression algorithms, we validate the effectiveness of RegTAF, identify the key threat dimensions governing severity assessment, and provide complexity analysis with different regression algorithms. By implementing RegTAF, high-threat or potentially harmful threat entities can be selected based on fine-grained threat severity, thereby improving the efficiency of web attack detection analysis.
KW - Intrusion detection
KW - Regression analysis
KW - Threat assessment
KW - Web attack detection
UR - https://www.scopus.com/pages/publications/105046206016
U2 - 10.1007/978-981-92-2868-3_10
DO - 10.1007/978-981-92-2868-3_10
M3 - 会议稿件
AN - SCOPUS:105046206016
SN - 9789819228676
T3 - Lecture Notes in Computer Science
SP - 118
EP - 128
BT - Knowledge Science, Engineering and Management - 19th International Conference, KSEM 2026, Proceedings
A2 - Niu, Jianwei
A2 - Qiu, Meikang
A2 - Cao, Cungen
PB - Springer Science and Business Media Deutschland GmbH
T2 - 19th International Conference on Knowledge Science, Engineering and Management, KSEM 2026
Y2 - 17 July 2026 through 19 July 2026
ER -