FAF-BM: An Approach for False Alerts Filtering Using BERT Model with Semi-supervised Active Learning
摘要
In the field of cybersecurity, the deluge of alerts presents a significant challenge to human review capabilities. Despite existing solutions, there is still an urgent need for more advanced methods to improve the effectiveness and accuracy of false alerts filtering. In this paper, we propose FAF-BM, a cutting-edge approach that integrates the BERT model, semi-supervised learning and active learning to enhance alert filtering capabilities. FAF-BM leverages the fine-tuned BERT model to fully exploit the deep semantics of alerts without being constrained by the format of the alerts. Subsequently, the semi-supervised learning is dedicated to mining the hidden potential within unlabeled data, thus expanding the learning scope beyond the confines of labeled datasets. In addition, the active learning strategically utilizes the expertise of security professionals to guide the learning process, ensuring that the approach adapts to the evolving threat landscape. Through a series of experiments, it has been demonstrated that FAF-BM not only improves the effectiveness of the filter but also enhances the generalization ability of dealing with the heterogeneity of alerts.