JSAI2023

Presentation information

General Session

General Session » GS-10 AI application

[2N1-GS-10] AI application

Wed. Jun 7, 2023 9:00 AM - 10:40 AM Room N (D2)

座長:大川 佳寛(富士通) [現地]

9:40 AM - 10:00 AM

[2N1-GS-10-03] pAUC Maximization Method for Log Analysis Robust to Overfitting and Noisy Labels

〇Taishi Nishiyama1, Atsutoshi Kumagai2, Akinori Fujino2, Kazunori Kamiya1 (1. NTT Security, 2. NTT)

Keywords:AUC, Malware detection, Log Analysis

To mitigate the damage caused by malware, network log analysis with machine learning for detecting suspicious logs has been attracting attention. In actual security operation, the true positive rate (TPR) in a low false positive rate (FPR) is important since operators must detect as many suspicious logs as possible while suppressing false positives. This paper focuses on the partial area under the curve (pAUC) maximization method that directly maximize the TPR in an arbitrary FPR interval. However, when using the previous pAUC maximization methods in actual operation, the classifier prone to overfitting and the classification performance tends to be deteriorate if there are mislabelings in the training data. To solve the problems, we propose the method that combines the AUC maximization and pAUC maximization method according to the mathematical characteristics of the features. We also demonstrate the effective of proposed method with proxy logs from a real-world large enterprise network.

Authentication for paper PDF access

A password is required to view paper PDFs. If you are a registered participant, please log on the site from Participant Log In.
You could view the PDF with entering the PDF viewing password bellow.

Password