行为建模
计算机科学
行为模式
内部威胁
异常检测
入侵检测系统
图形
事件(粒子物理)
财产(哲学)
数据挖掘
计算机安全
人工智能
理论计算机科学
知情人
软件工程
法学
哲学
物理
认识论
量子力学
政治学
标识
DOI:10.1109/tifs.2022.3191493
摘要
The so-calledbehavioral anomaly detection(BAD) is expected to solve effectively a variety of security issues by detecting the deviances from normal behavioral patterns of protected agents. We propose a new graph-based behavioral modeling paradigm for BAD problem, namedbehavioral identification graph(BIG), which has distinct advantages over existing methods by mining deeply theproperty-level(as an enhancement to theevent-level) associations in behavioral data. Under BIG, the behavioral properties and their co-occurrence associations in behavioral data are modeled as the entities and relationships of graph, respectively; furthermore, behavioral properties and events are both vectorized by a devised event-property composite model, and the behavioral patterns of agents are finally represented as a multidimensional spatial distribution of behavioral properties. Consequently, for a behavior, the intensity of its behavioral anomaly can be transformed into the spatial decentrality of its behavioral agent and properties which contain both fine-grained information between behavioral properties and coarse-grained information between behavioral events. To the best of our knowledge, this is the first work to improve behavioral modeling for anomaly detection by integratinginter(event-level) andintra(property-level) associations of behaviors into a unified graph and space. Our method is validated by four representative security issues, i.e.,fraud detectionin online payment services (by transaction behaviors),intrusion detectionin network communication services (by traffic behaviors),insider threat detectionin organizational information systems (by system behaviors), andcompromise detectionin social networking services (by trajectory behaviors).
科研通智能强力驱动
Strongly Powered by AbleSci AI