PulseAugur
中
实时 02:33:35
English(EN) From CVE to CWE: Syscall-Based HIDS Generalisation

基于系统调用的 HIDS 泛化在 CVE 和 CWE 中进行测试

研究人员调查了利用系统调用跟踪的主机入侵检测系统 (HIDS) 的泛化能力。该研究实证测试了在共享同一通用弱点枚举 (CWE) 类的已知通用漏洞和暴露 (CVE) 上训练的异常检测器是否能够识别同一类中新的、未见的 CVE。研究结果表明,虽然使用当前的系统调用特征可以实现某些弱点家族的 CWE 级别泛化,但并非普遍有效,并且可能具有方向依赖性。研究还强调了校准误报率对于该领域可靠报告的重要性。 AI

影响 这项研究可能带来更强大的入侵检测系统,能够根据已知的弱点类别识别新的威胁。

排序理由 学术论文,详细介绍了一种新的 HIDS 泛化方法。[lever_c_demoted from research: ic=1 ai=1.0]

在 arXiv cs.AI 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

基于系统调用的 HIDS 泛化在 CVE 和 CWE 中进行测试

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
学术论文,详细介绍了一种新的 HIDS 泛化方法。[lever_c_demoted from research: ic=1 ai=1.0]
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
paper, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
101 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

完整方法见我们的编辑标准。

报道来源 [1]

  1. arXiv cs.AI TIER_1 English(EN) · Shamil G. Magomedov ·

    从 CVE 到 CWE:基于系统调用的 HIDS 通用化

    Host intrusion detection systems (HIDS) based on system-call traces are typically trained and evaluated against individual Common Vulnerabilities and Exposures (CVE) instances. In operational settings, however, defenders need to recognise new exploits of an already known type of …