When Relationships Break: Interpreting Network Traffic Anomalies via Dependency Violations
Current research on security monitoring is increasingly focusing on machine-learning-based approaches, but caveats remain. In addition to huge computational overhead, one concern is the lack of insights into"why"alerts are raised. Existing interpretability approaches rely on feature attribution methods that ignore depe...