Abstract
Intrusion detection systems (IDS) are critical components of cybersecurity, tasked with identifying and responding to malicious activities. IDS primarily relies on the rules or classification methods to detect anomalies. Rule-based IDSs operate by comparing network traffic against a predefined set of rules to detect anomalies, but they often result in a high false positive rate because they cannot adapt to new scenes. Classification-based IDSs use machine learning algorithms to categorize network traffic as either benign or malicious. These systems often struggle with the granularity required for accurate threat assessment, because the amount of data can overwhelm these systems, leading to important threat indicators being overlooked. To address these limitations, this paper introduces Themis, a novel regression-based framework designed to evaluate and analyze threats present in multi-source security logs. Themis begins by extracting threat entities from web alert logs, which include critical information such as security events and threat IP addresses. These entities are then represented in a multidimensional space, where each dimension corresponds to a specific attribute of the threat entity. To overcome the challenges of data scarcity and class imbalance in security logs, Themis employs unsupervised learning techniques to enhance the features of threat entity samples. The core of Themis is a threat assessment model that leverages these enhanced features to perform threat regression analysis. This model is trained to predict the severity of threats, providing a more precise assessment than traditional intrusion detection methods. To validate the effectiveness of Themis, we conduct detailed regression analysis experiments to explore the dimensions that significantly impact threat severity, as identified through regression analysis. The ablation experiments that demonstrate the benefits of feature-enhanced threat assessment. Furthermore, we compare different regression algorithms used in threat assessment, discussing their respective advantages and disadvantages. Finally, we offer a complexity analysis and practical application recommendations for the various regression algorithms considered.
| Translated title of the contribution | 多源安全日志威胁量化分析 |
|---|---|
| Original language | English |
| Journal | Journal of Cyber Security |
| Volume | 11 |
| Issue number | 2 |
| DOIs | |
| State | Published - Mar 2026 |
| Externally published | Yes |
Keywords
- feature enhancement
- intrusion detection
- regression analysis
- threat assessment
Fingerprint
Dive into the research topics of 'Quantitative Threat Analysis of Multi-source Security Logs'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver