Skip to content

Implementing a Security Operations Baseline Through Process Tree Modeling for Network Security Situational Awareness

Sep 2026 · International Journal of Computational Intelligence and Applications · 0 citations · 20 references

TL;DR

A novel NSSA framework based on process tree modeling and dynamic service-chain orchestration that significantly outperforms PCA and Basic Evolution in terms of true positive and false positive rates, while the dynamic service-chain mechanism ensures efficient resource utilization and rapid threat containment.

Abstract

Network security situational awareness (NSSA) has become a critical requirement for modern cyber-infrastructures to promptly identify threats and dynamically mitigate risks. However, existing NSSA approaches often suffer from inaccurate behavioral baselines, high false positive rates, and inflexible defensive responses. To address these limitations, this paper proposes a novel NSSA framework based on process tree modeling and dynamic service-chain orchestration. Specifically, a process tree-based behavioral baseline is constructed to capture normal network operations with structural and temporal dependencies. An anomaly-detection pipeline is designed by integrating multi-source heterogeneous data and employing advanced feature selection techniques, including Statistical Process Embedding (SPE), PCA, and evolutionary strategies. Detected anomalies trigger a dynamic adjustment of the security service chain, leveraging NFV and SDN technologies to reconfigure virtual and physical security functions on demand. Extensive experiments using CICIDS2017 and real-world traces demonstrate the proposed framework’s effectiveness in accurately detecting anomalous activities, reducing false positives, and improving dynamic defensive responsiveness. The SPE-based feature selection significantly outperforms PCA and Basic Evolution in terms of true positive and false positive rates, while the dynamic service-chain mechanism ensures efficient resource utilization and rapid threat containment.

View source

Similar papers

Conference Open access 2025

Adaptive Behavioral Anomaly Detection: Integrating UEBA and EDR for Real-Time Mitigation of Threats and Insider Risks

: This research presents a comprehensive hybrid security system integrating User and Entity Behavior Analytics (UEBA) with Endpoint Detection and Response (EDR) capabilities to address sophisticated cyber threats including Advanced Persistent Threats (APTs) and insider attacks. The proposed architecture leverages the E...

A. Landge, Smita M. Chaudhari, Soham G. Jadhav et al. · 0 citations
Open access Sep 2026

A rule-driven SOC architecture for real-time threat detection and autonomous incident response

Security Operations Centers (SOCs) are essential for monitoring and responding to cyber threats in cloud-native environments, where infrastructure is dynamic, multi-tenant, and API-driven. Conventional SOCs rely heavily on manual triage and SIEM-based alerting, resulting in delayed detection of cloud-specific attacks s...

Jilika Jithendarnadh, J. Balaraju · 0 citations
Open access 2026

Real-Time Cyber Situational Awareness for 6G Networks Leveraging Spatial Metrics

The dynamic and heterogeneous nature of 6G networks demands continuous, real-time cyber situational awareness (CSA) to support cognitive security operations such as behavior analysis, threat hunting, and adaptive defense. Traditional CSA frameworks like CRUSOE capture structural and mission-level data but cannot proces...

José Antonio Pastor Valera, M. Husák, J. García-Rodríguez et al. · 0 citations
Preprint Aug 2026

Defending the Peg: Real-Time Dynamic Protection and Anomaly Detection in DeFi Stablecoins

With the rapid evolution of the Decentralized Finance (DeFi) ecosystem, stablecoins have emerged as a critical infrastructure bridging the cryptocurrency market with traditional financial paradigms. However, stablecoin systems rely heavily on smart contracts to execute automated operations. The immutable nature of thes...

Heng-Xing Zeng, Shi-Peng Ye, Xiao-Qi Li · 0 citations
Open access Aug 2026

Adaptive Threat Intelligence Framework for Real-Time Cyberattack Detection Using Behavior-Based Analytics

The rapid growth of interconnected digital infrastructures, cloud computing environments, Internet of Things devices, and enterprise networking systems has significantly increased the frequency, complexity, and sophistication of cyberattacks targeting organizational information assets. Traditional cybersecurity mechani...

S. Tamilselvi · 0 citations
Review Open access Aug 2026

A Review of Protocol Analysis-Based Secure Traffic Monitoring and Anomalous Behavior Detection Technologies for Power Monitoring Systems

The review begins with the network architecture, representative protocols such as IEC 104, IEC 61850, and Distributed Network Protocol 3 (DNP3), and their associated security risks, thereby clarifying the foundational role of protocol-level visibility in power monitoring scenarios.

Shan-Shan Bai, Pengyuan Wang, Tian-Le Gao et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.