<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Declarative Pattern Mining in Network Security</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Gioacchino Sterlicchio</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Francesca Alessandra Lisi</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>DIB and CILA, University of Bari Aldo Moro</institution>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>DMMM, Polytechnic University of Bari</institution>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>This work addresses the problem of detecting patterns of attacks on 4G-LTE network security by relying on the Contrast Sequential Pattern Mining (CSPM) task leveraging the declarative framework of Answer Set Programming (ASP). Pattern mining is widely applied for diferent application in network security; see Buczak et al. [1] for a survey. Whereas sequence mining is extensively explored in network security, the Contrast Sequential Pattern Mining (CSPM) task [2] has not been addressed so far in this application domain to the best of our knowledge. In this extended abstract, we consider the problem of detecting patterns of attacks to 4G-LTE network security relying on the CSPM task. Our approach, fully described in [3], utilizes the declarative framework of Answer Set Programming (ASP) [4], thereby aligning with the research area known as Declarative Pattern Mining (DPM) [5, 6, 7]. In particular, Guyet et al. [5] describes the first proposal of an ASP-based approach to sequence mining and compares it with a dedicated algorithm. Later, Guyet et al. [7] introduce ASP encodings for two representations of embeddings (fill-gaps vs. skip-gaps) in sequence mining. Lisi and Sterlicchio [8] introduced the initial ASP formulation for the CSPM issue, which we will call Mining with Answer Set Solving - Contrast Sequential Patterns (MASS-CSP) from now on. When tackling the DPM challenges related to network security, our work in [3] enhances both the performance and efectiveness of MASS-CSP by incorporating span and gap restrictions during the sequence mining phase. We then perform a comparative evaluation using trace sets from two types of network attack: authentication failure and numb attacks [9]. The paper is organized as follows. In Section 2 and 3 we briefly describe the MASS-CSP approach , and report some evaluation results obtained on sets of traces for the numb attack, respectively. Section 4 concludes the paper with final remarks.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Answer Set Programming</kwd>
        <kwd>Declarative Pattern Mining</kwd>
        <kwd>Contrast Sequential Pattern Mining</kwd>
        <kwd>Network Security</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
    </sec>
    <sec id="sec-2">
      <title>2. The MASS-CSP approach with span/gap constraints</title>
      <p>We begin by making a couple of observations regarding the constraints of MASS-CSP. To illustrate,
consider the pattern ⟨, ⟩ along with the sequences ⟨, , ⟩ and ⟨, , , ⟩. First, the number of gaps
between successive embeddings is not addressed. In other words, within a sequence, two neighboring
elements of a sequential pattern may be separated by  gaps, which is 0 and 2 in the given example.
Secondly, ⟨, ⟩ appears in both sequences but exhibits diferent spans, specifically 1 and 3, respectively.
Our study builds on these insights because in many application areas, patterns exhibiting certain
properties are more informative.</p>
      <p>
        Many types of constraints on patterns and embeddings for sequence mining are available in the
literature [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. The span constraint refers to setting a limit on the length of the sequential patterns
being analyzed. This means that when searching for patterns, only those that fall within a specified
minimum and maximum length are considered valid. For example, if the minimum length is 3 and the
maximum length is 5, patterns shorter than 3 or longer than 5 will not be included in the results. The
gap constraint involves regulating the gap allowed between consecutive occurrences of items within a
sequence. This helps in controlling how close or far apart items in a pattern can appear. For instance, if
the minimum gap is 1 and the maximum gap is 3, then each subsequent item in the pattern must appear
at least 1 but not more than 3 positions after the previous item. These constraints help in refining the
search process to find more relevant or interesting patterns by filtering out those patterns that do not
meet the specified criteria.
      </p>
      <p>
        As noted by [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], we opted to encode these constraints as choice rules rather than ASP denials, thereby
integrating them into the generation phase to reduce the search space proactively. Detailed encoding
and additional information are available in [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. This approach has led to enhanced eficiency and
efectiveness of the final output, as discussed in the next section.
      </p>
    </sec>
    <sec id="sec-3">
      <title>3. Experimental results</title>
      <p>
        CSPM can be particularly useful to 4G-LTE. It does this by analyzing sequences of network events
to identify patterns that help in making better decisions regarding network configurations, resource
allocations, and managing network trafic, all while ensuring that quality of service standards are
met. CSPM can detect abnormal or suspicious network activities, which can signify potential security
threats. By analyzing these patterns, it is s possible to diferentiate between normal and potentially
harmful behaviors. Our emphasis is on security, and finding contrast sequential patterns can reveal
anomalies or irregularities in network activity, aiding in the identification of possible security risks.
These patterns illustrate typical and malicious behavior as reflected in various traces. Our work considers
the authentication failure attack and the numb attack as a case study for which we used the traces made
available by [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]1. As an illustration, Listing 1 shows an example of contrast sequential pattern for the
numb attack. It is the longest pattern found having 30% support across all sequences, and describes the
timeline of events that leads to the attack.
      </p>
      <sec id="sec-3-1">
        <title>Listing 1: Example of pattern found with 30% support in Numb_Attack_40.</title>
        <p>&lt; a t t a c h _ r e q u e s t , a u t h e n t i c a t i o n _ r e q u e s t , a u t h e n t i c a t i o n _ r e s p o n s e ,
security_mode_command , s e c u r i t y _ m o d e _ c o m p l e t e , a t t a c h _ a c c e p t ,
a t t a c h _ c o m p l e t e , d e t a c h _ r e q u e s t , d e t a c h _ a c c e p t , a t t a c h _ r e q u e s t ,
a u t h e n t i c a t i o n _ r e q u e s t , a u t h e n t i c a t i o n _ r e s p o n s e , security_mode_command ,
s e c u r i t y _ m o d e _ c o m p l e t e , a t t a c h _ a c c e p t , a t t a c h _ c o m p l e t e &gt;</p>
        <p>
          The primary aim of the evaluation is to demonstrate the practicality of using a declarative approach
for CSPM within network security. Additionally, the experiments are structured to ofer a comparative
assessment between the original MASS-CSP documented in [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ] and its enhanced version incorporating
the span/gap constraints. In [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ], we provide empirical evidence demonstrating the benefits of introducing
additional constraints on pattern embeddings. Figure 1 compares the standard MASS-CSP (represented
by dotted lines) with the enhanced MASS-CSP (depicted by continuous lines) in the context of the numb
attack.
        </p>
        <p>By setting minimum and maximum gap constraints, the process refines and controls the types
of patterns generated, ensuring that only relevant patterns are produced. This refinement reduces
computational output and enhances eficiency by saving time during the pattern generation phase.
However, in terms of memory usage, it is not much variation as the values remain similar or slightly
increase. Overall, the gap constraint is highlighted for its performance improvements, particularly in
minimizing extraneous patterns and expediting the process without adversely afecting memory usage
significantly. By implementing the span constraint, we can decrease the number of patterns and reduce
1https://github.com/CLC-UIowa/SySLite
execution time. However, this approach does not lead to any improvements in memory usage and may
actually require more storage space. In contrast, using the gap constraint ofers the greatest benefits,
significantly enhancing overall performance.</p>
        <p>(a)</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Conclusion</title>
      <p>This research investigates the detection of attack patterns of the 4G LTE network security, focusing
on attacks like authentication failure and the numb attack. We leverage Contrast Sequential Pattern
Mining (CSPM) implemented using Answer Set Programming (ASP) to analyze 4G LTE network trafic
behavior. This method allows us to identify sequential patterns that diferentiate between normal
and attack-related network behavior. The resulting patterns are valuable for understanding attack
progression and creating efective countermeasures.</p>
      <p>The research demonstrates that using a declarative method for detecting network security attacks is
possible. By incorporating specific constraints — namely span and gap constraints — the system becomes
more eficient by reducing the number of patterns it needs to process. This leads to lower memory usage
and faster execution times. Additionally, because the approach is based solely on analyzing execution
traces, it is highly adaptable and can be applied to various types of attacks across diferent network
systems, including advanced technologies like 5G. This versatility ensures that the method remains
relevant and efective as network technologies evolve.</p>
    </sec>
    <sec id="sec-5">
      <title>Acknowledgments</title>
      <p>This work was partially supported by the project FAIR - Future AI Research (PE00000013), under the
NRRP MUR program funded by the NextGenerationEU.</p>
    </sec>
    <sec id="sec-6">
      <title>Declaration on Generative AI</title>
      <sec id="sec-6-1">
        <title>The author(s) have not employed any Generative AI tools.</title>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>A. L.</given-names>
            <surname>Buczak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Guven</surname>
          </string-name>
          ,
          <article-title>A survey of data mining and machine learning methods for cyber security intrusion detection</article-title>
          ,
          <source>IEEE Communications surveys &amp; tutorials 18</source>
          (
          <year>2015</year>
          )
          <fpage>1153</fpage>
          -
          <lpage>1176</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Gan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Wu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. S.</given-names>
            <surname>Yu</surname>
          </string-name>
          , Contrast pattern mining: A survey,
          <year>2022</year>
          . arXiv:
          <volume>2209</volume>
          .
          <fpage>13556</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>G.</given-names>
            <surname>Sterlicchio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F. A.</given-names>
            <surname>Lisi</surname>
          </string-name>
          ,
          <article-title>Detecting patterns of attacks to network security in urban air mobility with answer set programming</article-title>
          , in: U.
          <string-name>
            <surname>Endriss</surname>
            ,
            <given-names>F. S.</given-names>
          </string-name>
          <string-name>
            <surname>Melo</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          <string-name>
            <surname>Bach</surname>
            ,
            <given-names>A. J. B.</given-names>
          </string-name>
          <string-name>
            <surname>Diz</surname>
          </string-name>
          ,
          <string-name>
            <surname>J. M. AlonsoMoral</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Barro</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          <string-name>
            <surname>Heintz</surname>
          </string-name>
          (Eds.),
          <source>ECAI 2024 - 27th European Conference on Artificial Intelligence</source>
          ,
          <fpage>19</fpage>
          -24
          <source>October</source>
          <year>2024</year>
          , Santiago de Compostela,
          <source>Spain - Including 13th Conference on Prestigious Applications of Intelligent Systems (PAIS</source>
          <year>2024</year>
          ), volume
          <volume>392</volume>
          <source>of Frontiers in Artificial Intelligence and Applications</source>
          , IOS Press,
          <year>2024</year>
          , pp.
          <fpage>1285</fpage>
          -
          <lpage>1292</lpage>
          . URL: https://doi.org/10.3233/FAIA240626. doi:
          <volume>10</volume>
          . 3233/FAIA240626.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>V.</given-names>
            <surname>Lifschitz</surname>
          </string-name>
          ,
          <article-title>Answer sets and the language of answer set programming</article-title>
          ,
          <source>AI</source>
          Magazine
          <volume>37</volume>
          (
          <year>2016</year>
          )
          <fpage>7</fpage>
          -
          <lpage>12</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>T.</given-names>
            <surname>Guyet</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Moinard</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Quiniou</surname>
          </string-name>
          ,
          <article-title>Using answer set programming for pattern mining</article-title>
          ,
          <source>arXiv preprint arXiv:1409.7777</source>
          (
          <year>2014</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>M.</given-names>
            <surname>Gebser</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Guyet</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Quiniou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Romero</surname>
          </string-name>
          , T. Schaub,
          <article-title>Knowledge-based sequence mining with ASP</article-title>
          ,
          <source>in: IJCAI 2016-25th International joint conference on artificial intelligence, AAAI</source>
          ,
          <year>2016</year>
          , p.
          <fpage>8</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>T.</given-names>
            <surname>Guyet</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Moinard</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Quiniou</surname>
          </string-name>
          , T. Schaub,
          <article-title>Eficiency analysis of ASP encodings for sequential pattern mining tasks</article-title>
          ,
          <source>in: Advances in Knowledge Discovery and Management</source>
          , Springer,
          <year>2018</year>
          , pp.
          <fpage>41</fpage>
          -
          <lpage>81</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>F. A.</given-names>
            <surname>Lisi</surname>
          </string-name>
          , G. Sterlicchio,
          <article-title>Mining contrast sequential patterns with ASP</article-title>
          , in: R.
          <string-name>
            <surname>Basili</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          <string-name>
            <surname>Lembo</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          <string-name>
            <surname>Limongelli</surname>
            ,
            <given-names>A</given-names>
          </string-name>
          . Orlandini (Eds.),
          <source>AIxIA 2023 - Advances in Artificial Intelligence - XXIInd International Conference of the Italian Association for Artificial Intelligence</source>
          ,
          <source>AIxIA</source>
          <year>2023</year>
          , Rome, Italy, November 6-
          <issue>9</issue>
          ,
          <year>2023</year>
          , Proceedings, volume
          <volume>14318</volume>
          of Lecture Notes in Computer Science, Springer,
          <year>2023</year>
          , pp.
          <fpage>44</fpage>
          -
          <lpage>57</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>031</fpage>
          -47546-
          <issue>7</issue>
          _
          <fpage>4</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>S. R.</given-names>
            <surname>Hussain</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Chowdhury</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Mehnaz</surname>
          </string-name>
          , E. Bertino,
          <article-title>LTEInspector: A systematic approach for adversarial testing of 4G LTE, in: 25th Annual Network and Distributed System Security Symposium</article-title>
          ,
          <string-name>
            <surname>NDSS</surname>
          </string-name>
          <year>2018</year>
          , San Diego, California, USA, February
          <volume>18</volume>
          -
          <issue>21</issue>
          ,
          <year>2018</year>
          , The Internet Society,
          <year>2018</year>
          . URL: https: //www.ndss-symposium.org/wp-content/uploads/2018/02/ndss2018_
          <fpage>02A</fpage>
          -
          <lpage>3</lpage>
          _Hussain_paper.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>J.</given-names>
            <surname>Pei</surname>
          </string-name>
          , J. Han,
          <string-name>
            <surname>W</surname>
          </string-name>
          . Wang,
          <article-title>Constraint-based sequential pattern mining: the pattern-growth methods</article-title>
          ,
          <source>Journal of Intelligent Information Systems</source>
          <volume>28</volume>
          (
          <year>2007</year>
          )
          <fpage>133</fpage>
          -
          <lpage>160</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>G.</given-names>
            <surname>Sterlicchio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F. A.</given-names>
            <surname>Lisi</surname>
          </string-name>
          ,
          <article-title>Detecting Patterns of Attacks to Network Security in Urban Air Mobility with Answer Set Programming</article-title>
          ,
          <year>2024</year>
          . URL: https://doi.org/10.5281/zenodo.13135192.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>M. F.</given-names>
            <surname>Arif</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Larraz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Echeverria</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Reynolds</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Chowdhury</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Tinelli</surname>
          </string-name>
          , Syslite:
          <article-title>Syntax-guided synthesis of PLTL formulas from finite traces</article-title>
          ,
          <source>in: 2020 Formal Methods in Computer Aided Design (FMCAD)</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>93</fpage>
          -
          <lpage>103</lpage>
          . doi:
          <volume>10</volume>
          .34727/2020/isbn.978-3-
          <fpage>85448</fpage>
          -042-6_
          <fpage>16</fpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>