Analyzing Data Granularity Levels for Insider Threat Detection Using Machine Learning

内部威胁 知情人 计算机科学 粒度 计算机安全 机器学习 集合(抽象数据类型) 人工智能 政治学 操作系统 程序设计语言 法学
作者
Duc C. Le,A. Nur Zincir‐Heywood,Malcolm I. Heywood
出处
期刊:IEEE Transactions on Network and Service Management [Institute of Electrical and Electronics Engineers]
卷期号:17 (1): 30-44 被引量:116
标识
DOI:10.1109/tnsm.2020.2967721
摘要

Malicious insider attacks represent one of the most damaging threats to networked systems of companies and government agencies. There is a unique set of challenges that come with insider threat detection in terms of hugely unbalanced data, limited ground truth, as well as behaviour drifts and shifts. This work proposes and evaluates a machine learning based system for user-centered insider threat detection. Using machine learning, analysis of data is performed on multiple levels of granularity under realistic conditions for identifying not only malicious behaviours, but also malicious insiders. Detailed analysis of popular insider threat scenarios with different performance measures are presented to facilitate the realistic estimation of system performance. Evaluation results show that the machine learning based detection system can learn from limited ground truth and detect new malicious insiders in unseen data with a high accuracy. Specifically, up to 85% of malicious insiders are detected at only 0.78% false positive rate. The system is also able to quickly detect the malicious behaviours, as low as 14 minutes after the first malicious action. Comprehensive result reporting allows the system to provide valuable insights to analysts in investigating insider threat cases.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
1秒前
1秒前
齐齐完成签到,获得积分10
1秒前
刘龙应助FG采纳,获得10
1秒前
吴3L发布了新的文献求助10
2秒前
2秒前
3秒前
3秒前
3秒前
3秒前
11完成签到,获得积分10
4秒前
刘xiansheng发布了新的文献求助10
4秒前
丘比特应助吕程校采纳,获得10
5秒前
田様应助EndNoteX4采纳,获得10
5秒前
李健的小迷弟应助白白白采纳,获得10
5秒前
曾无忧应助感动代双采纳,获得10
5秒前
任彦蓉完成签到,获得积分10
5秒前
6秒前
爆米花应助Anzu采纳,获得10
6秒前
隶书发布了新的文献求助10
6秒前
pol发布了新的文献求助10
6秒前
7秒前
蔡小熊完成签到 ,获得积分10
7秒前
香蕉觅云应助KaiYuaN采纳,获得10
7秒前
7秒前
从容雅柏发布了新的文献求助10
8秒前
dawn完成签到,获得积分10
8秒前
8秒前
李爱国应助快乐耶耶耶采纳,获得10
8秒前
科研通AI6.3应助sss的擎宇采纳,获得10
9秒前
小白猫发布了新的文献求助10
9秒前
9秒前
海山了发布了新的文献求助10
9秒前
9秒前
bellapp发布了新的文献求助30
10秒前
10秒前
Ryzen完成签到,获得积分10
10秒前
落叶发布了新的文献求助10
10秒前
NexusExplorer应助coastlines采纳,获得10
11秒前
12秒前
高分求助中
GL 2 A method for assessing the in-place cleanability of food processing equipment, Fourth Edition, December 2023 3000
Annie Ernaux: De la perte au corps glorieux 600
Microvascular Surgery in Head and Neck Reconstruction 500
Petrology and Plate Tectonics 500
Writing Systems 500
Media Today Mass Communication in a Converging World 9th Edition 400
Understanding Modeling and Simulation of Polymerization Reactions 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6839179
求助须知:如何正确求助?哪些是违规求助? 8547778
关于积分的说明 18186394
捐赠科研通 6187218
什么是DOI,文献DOI怎么找? 3039410
关于科研通互助平台的介绍 2028489
邀请新用户注册赠送积分活动 2016971