---
格式版本: 2
标题: "Slips: Behavioral Evidence Aggregation for Network Security"
原文链接: "https://arxiv.org/abs/2608.11979"
发布日期: "2026-08-12"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Wed, 12 Aug 2026 12:12:55 UTC (1,462 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-13T18:33:56+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-13T18:24:32+08:00"
入库时间: "2026-08-13T10:33:56.491Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=AI&searchtype=all"
匹配关键词:
  - "AI"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI质检状态: "评分失败"
AI评分尝试次数: 1
AI评分错误类型: "service_error"
AI评分错误: "LLM call failed; tried model chain: ali-deepseek-v4-flash -> tx-deepseek-v4-flash | Model ali-deepseek-v4-flash failed 500: {\"error\":{\"code\":\"\",\"message\":\"Database error, please contact the administrator (request id: 202608131033592370876138268d9d6YLE3pthz)\",\"type\":\"new_api_error\"}} | Model tx-deepseek-v4-flash failed 500: {\"error\":{\"code\":\"\",\"message\":\"Database error, please contact the administrator (request id: 202608131033597880324708268d9d6a4ZYiCvo)\",\"type\":\"new_api_error\"}}"
AI评分开始时间: "2026-08-13T10:33:56.593Z"
AI评分结束时间: "2026-08-13T10:33:59.923Z"
AI摘要: "Slips 是一种网络入侵检测系统，通过构建主机行为画像并按时间窗口聚合各模块证据来生成告警。在专家标注的 PCAP 数据集上，相比 Suricata，Slips 的召回率提高 83%、F1 分数提高 70%，且双方均无假阳性。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:39:53.933Z"
采集批次: "2026年8月13日18点24分27秒"
采集批次ID: "20260813-182427-1564e572"
去重键: "https://arxiv.org/abs/2608.11979"
---

## Computer Science > Cryptography and Security

## Title:Slips: Behavioral Evidence Aggregation for Network Security

[View PDF](https://arxiv.org/pdf/2608.11979) [HTML (experimental)](https://arxiv.org/html/2608.11979v1)

> Abstract:Network intrusion detection systems often analyze individual packets or flows, although malicious behavior may develop across many connections and over time. This may limit their ability to combine isolated detections into a coherent assessment of host behavior. Packet-level features may also be too low-level for complex AI-based detection, requiring additional processing to improve accuracy while maintaining a low false-positive rate.  
> We present Slips, a network intrusion detection system that builds host-centered behavioral profiles and organizes activity into time windows. It uses a modular architecture in which independent modules report evidence rather than generating final alerts directly. Slips then accumulates this evidence into host-level decisions. We evaluate Slips against Suricata on an expert-labeled PCAP dataset. At the profile-time-window level, Slips achieved 83% higher recall and a 70% higher F1 score than Suricata, while neither system produced false positives. These results indicate that time-window-based evidence accumulation can produce context-aware decisions that better align with expert judgment.

| Subjects: | Cryptography and Security (cs.CR) |
| --- | --- |
| Cite as: | [arXiv:2608.11979](https://arxiv.org/abs/2608.11979) \[cs.CR\] |
|  | (or [arXiv:2608.11979v1](https://arxiv.org/abs/2608.11979v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.11979](https://doi.org/10.48550/arXiv.2608.11979) |

## Submission history

From: Veronica Valeros \[[view email](https://arxiv.org/show-email/c81e65f9/2608.11979)\]  
**\[v1\]** Wed, 12 Aug 2026 12:12:55 UTC (1,462 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.11979) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
