ETRI-Knowledge Sharing Plaform

KOREAN
논문 검색
Type SCI
Year ~ Keyword

Detail

Journal Article HAECHI: Behavior-Aware Attacker-Centric Hierarchical Network Threat Detection Framework
Cited 0 time in scopus Share share facebook twitter linkedin kakaostory
Authors
Yujin So, Hyunjin Kim
Issue Date
2026-09
Citation
IEEE Internet of Things Journal, v.13, no.17, pp.38443-38458
ISSN
2327-4662
Publisher
IEEE
Language
English
Type
Journal Article
DOI
https://dx.doi.org/10.1109/JIOT.2026.3698058
Abstract
The growing complexity of modern network infrastructures, spanning private 5G networks, enterprise systems, and IoT deployments, has expanded the attack surface for multistage chained attacks that exploit structural dependencies across heterogeneous network layers. While the MITRE ATT&CK framework systematizes these attacker behaviors into tactics and techniques, most existing intrusion detection systems remain limited to binary or attack-type classification without attributing detected anomalies to specific attacker tactics. Identifying tactical intent at early stages of an attack scenario, rather than confirming threats only after damage has occurred, can help security operators anticipate subsequent attack stages and allocate defensive resources. However, general-purpose tokenizers tend to fragment domain-specific field-value pairs into sub-word units, which can obscure the behavioral context needed for tactic discrimination. To address these limitations, we propose HAECHI, a behavior-aware hierarchical threat detection framework that combines a domain-adaptive Transformer encoder with tactic-specific heads. The framework introduces a KV tokenization that preserves field-value relationships as atomic semantic units, a One-versus-Rest ensemble architecture that configures lightweight tactic-specific heads on a shared encoder to address inter-tactic heterogeneity and class imbalance, and a confidence-weighted voting mechanism that assigns differential weights based on each head’s validation performance. Experiments on a real-world private 5G testbed and two public benchmarks (CSE-CIC-IDS2018 and TON_ IoT) show consistent detection performance, outperforming the evaluated baselines across all datasets. Ablation studies and computational complexity analysis support the contribution of each component. This article contributes to tactic-level attack attribution in resource-constrained network environments.
Keyword
Ensemble learning, key-value (KV) tokenization, MITRE ATT&CK, network intrusion detection, tactic-level attribution, transformer
KSP Keywords
5G networks, Attack Surface, Attack attribution, Attack scenario, Behavior-aware, Computational complexity analysis, Detection Framework, Domain-specific, Early stages, Ensemble Learning, Intrusion Detection Systems(IDS)