Sep 2026· International Journal of Computational Intelligence and Applications· 0 citations· 20 references
TL;DR
A novel NSSA framework based on process tree modeling and dynamic service-chain orchestration that significantly outperforms PCA and Basic Evolution in terms of true positive and false positive rates, while the dynamic service-chain mechanism ensures efficient resource utilization and rapid threat containment.
Abstract
Network security situational awareness (NSSA) has become a critical requirement for modern cyber-infrastructures to promptly identify threats and dynamically mitigate risks. However, existing NSSA approaches often suffer from inaccurate behavioral baselines, high false positive rates, and inflexible defensive responses. To address these limitations, this paper proposes a novel NSSA framework based on process tree modeling and dynamic service-chain orchestration. Specifically, a process tree-based behavioral baseline is constructed to capture normal network operations with structural and temporal dependencies. An anomaly-detection pipeline is designed by integrating multi-source heterogeneous data and employing advanced feature selection techniques, including Statistical Process Embedding (SPE), PCA, and evolutionary strategies. Detected anomalies trigger a dynamic adjustment of the security service chain, leveraging NFV and SDN technologies to reconfigure virtual and physical security functions on demand. Extensive experiments using CICIDS2017 and real-world traces demonstrate the proposed framework’s effectiveness in accurately detecting anomalous activities, reducing false positives, and improving dynamic defensive responsiveness. The SPE-based feature selection significantly outperforms PCA and Basic Evolution in terms of true positive and false positive rates, while the dynamic service-chain mechanism ensures efficient resource utilization and rapid threat containment.
: This research presents a comprehensive hybrid security system integrating User and Entity Behavior Analytics (UEBA) with Endpoint Detection and Response (EDR) capabilities to address sophisticated cyber threats including Advanced Persistent Threats (APTs) and insider attacks. The proposed architecture leverages the E...
A. Landge, Smita M. Chaudhari, Soham G. Jadhav et al.· Proceedings of the 1st Inter...· 0 citations
Security Operations Centers (SOCs) are essential for monitoring and responding to cyber threats in cloud-native environments, where infrastructure is dynamic, multi-tenant, and API-driven. Conventional SOCs rely heavily on manual triage and SIEM-based alerting, resulting in delayed detection of cloud-specific attacks s...
Jilika Jithendarnadh, J. Balaraju· Review of Computer Engineeri...· 0 citations
The dynamic and heterogeneous nature of 6G networks demands continuous, real-time cyber situational awareness (CSA) to support cognitive security operations such as behavior analysis, threat hunting, and adaptive defense. Traditional CSA frameworks like CRUSOE capture structural and mission-level data but cannot proces...
José Antonio Pastor Valera, M. Husák, J. García-Rodríguez et al.· IEEE Transactions on Network...· 0 citations
With the rapid evolution of the Decentralized Finance (DeFi) ecosystem, stablecoins have emerged as a critical infrastructure bridging the cryptocurrency market with traditional financial paradigms. However, stablecoin systems rely heavily on smart contracts to execute automated operations. The immutable nature of thes...
Heng-Xing Zeng, Shi-Peng Ye, Xiao-Qi Li· 0 citations
The rapid growth of interconnected digital infrastructures, cloud computing environments, Internet of Things devices, and enterprise networking systems has significantly increased the frequency, complexity, and sophistication of cyberattacks targeting organizational information assets. Traditional cybersecurity mechani...
S. Tamilselvi· Journal of Intelligent Decis...· 0 citations
The review begins with the network architecture, representative protocols such as IEC 104, IEC 61850, and Distributed Network Protocol 3 (DNP3), and their associated security risks, thereby clarifying the foundational role of protocol-level visibility in power monitoring scenarios.
Shan-Shan Bai, Pengyuan Wang, Tian-Le Gao et al.· Journal of Electronics and E...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.