内部威胁
计算机科学
知情人
计算机安全
图形
嵌入
节点(物理)
理论计算机科学
数据挖掘
人工智能
政治学
结构工程
工程类
法学
作者
Tian Tian,Yiru Gong,Bo Jiang,Junrong Liu,Huamin Feng,Zhigang Lu
标识
DOI:10.1109/trustcom60117.2023.00096
摘要
As one of the most challenging threats in cyberspace, insider threats frequently lead to substantial losses for enterprises. Recently, there are many studies focus on user behavior analysis for insider threats detection. However, they ignore the underlying causes of insider threats and the implicit relationships between users, which is more critical for discover the insider threats. To address this gap, we propose the novel ITDE model in this paper, which applies a graph neural network approach based on two-layer attention. The core idea is to abstracting user features and potential relationships as heterogeneous graphs based on an analysis of user behavior and the causes of insider threats. Futhermore, we employ node-level attention and semantic-level attention to capture the complex graph structure information and generate node embedding by aggregating features from meta-path based neighbors. Finally, we use a cross-entropy loss function to implement insider threat detection. We verify the effectiveness of our model on the CERT r4.2 dataset and it outperforms state-of-the-art methods in insider threat detection.
科研通智能强力驱动
Strongly Powered by AbleSci AI