FINDING · EVALUATION

At operationally realistic base rates—1 million connection pairs per hour with only 10 true stepping-stone chains—a detector with a 1% FPR generates approximately 10,000 false alarms per hour while correctly flagging all 10 intrusions, making classical statistical methods (which cannot reach FPR ≪ 10⁻²) operationally unusable; deep learning methods must target FPR ≤ 10⁻³ to be viable.

From 2026-mathews-tracing-chain-deepTracing the Chain: Deep Learning for Stepping-Stone Intrusion Detection · §I · 2026 · arXiv preprint

Implications

Tags

censors
generic
techniques
flow-correlationml-classifier

Extracted by claude-sonnet-4-6 — review before relying.