HoSig-Align I: Edge-Native Threat Attribution using Homology Blocks in IoT-Pervasive Networks
Résumé fourni par la source
A primary challenge in network defense is to mine potential attack campaigns from massive, continuously arriving alerts and telemetry data in real time. This paper presents HoSig-Align I, an edge side unsupervised method designed for network streams to discover homologous blocks. Our approach innovatively fuses heterogeneous features like Internet Protocol (IP) and Payload into a unified representation while strictly excluding temporal information from it, only incorporating time via a dual time scale decay model during graph construction to capture temporal proximity. A density robust similarity is computed using an isolation style random partition forest, leading to a sparse k-Nearest Neighbors (k-NN) graph. The stream is then accurately segmented into internally cohesive and mutually isolated homologous blocks through spectral ordering and contrastive change point detection. Each block is encoded into a lightweight HoSig signature, forming the basis for cross organizational collaboration. Experiments on real network streams show that HoSig-Align I identifies coherent attack campaign blocks and improves separation and boundary clarity over baselines, while meeting low-latency and low-overhead requirements for edge processing.
Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.
Contrôle bibliographique ouvert
DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.
- Titre Crossref
- HoSig-Align I: Edge-Native Threat Attribution using Homology Blocks in IoT-Pervasive Networks
- Date Crossref
- 16/03/2026
- Éditeur
- IEEE
- Type
- proceedings-article
Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude et ne compte pas comme une seconde source scientifique indépendante.
Institutions déclarées
Une affiliation ne permet pas de déduire la nationalité d’un auteur.