Abstract
A primary challenge in network defense is to mine potential attack campaigns from massive, continuously arriving alerts and telemetry data in real time. This paper presents HoSig-Align I, an edge side unsupervised method designed for network streams to discover homologous blocks. Our approach innovatively fuses heterogeneous features like Internet Protocol (IP) and Payload into a unified representation while strictly excluding temporal information from it, only incorporating time via a dual time scale decay model during graph construction to capture temporal proximity. A density robust similarity is computed using an isolation style random partition forest, leading to a sparse k-Nearest Neighbors (k-NN) graph. The stream is then accurately segmented into internally cohesive and mutually isolated homologous blocks through spectral ordering and contrastive change point detection. Each block is encoded into a lightweight HoSig signature, forming the basis for cross organizational collaboration. Experiments on real network streams show that HoSig-Align I identifies coherent attack campaign blocks and improves separation and boundary clarity over baselines, while meeting low-latency and low-overhead requirements for edge processing.
| Original language | English |
|---|---|
| Journal | Proceedings of the IEEE International Conference on Pervasive Computing and Communications, PerCom |
| Issue number | 2026 |
| DOIs | |
| State | Published - 2026 |
| Externally published | Yes |
| Event | 24th IEEE International Conference on Pervasive Computing and Communications, PerCom 2026 - Pisa, Italy Duration: 16 Mar 2026 → 20 Mar 2026 |
Keywords
- multimodal sensor fusion
- privacy preserving
- spectral graph clustering
- unsupervised stream segmentation
Fingerprint
Dive into the research topics of 'HoSig-Align I: Edge-Native Threat Attribution using Homology Blocks in IoT-Pervasive Networks'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver