paper-with-me

Papers

Fine Grained Insider Risk Detection

2024-11-04 · Birkett Huber, Casper Neo, Keiran Sampson, Alex Kantchelian, Brett Ksobiech, Yanis Pavlidis

We present a method to detect departures from business-justified workflows among support agents. Our goal is to assist auditors in identifying agent actions that cannot be explained by the activity within their surrounding context, where normal activity patterns are established from historical data. We apply our method to help audit millions of actions of over three thousand support agents. We collect logs from the tools used by support agents and construct a bipartite graph of Actions and Entities representing all the actions of the agents, as well as background information about entities. From this graph, we sample subgraphs rooted on security-significant actions taken by the agents. Each subgraph captures the relevant context of the root action in terms of other actions, entities and their relationships. We then prioritize the rooted-subgraphs for auditor review using feed-forward and graph neural networks, as well as nearest neighbors techniques. To alleviate the issue of scarce labeling data, we use contrastive learning and domain-specific data augmentations. Expert auditors label the top ranked subgraphs as `worth auditing" or `not worth auditing" based on the company's business policies. This system finds subgraphs that are worth auditing with high enough precision to be used in production.

📄 PDF Abstract BibTeX arXiv:2411.02645

Code (0)

등록된 구현이 없습니다.

Tasks

Contrastive Learning

Methods 이 논문이 사용한 방법론

Contrastive Learning 설명 없음

Similar Papers 제목 키워드 기반

ADSAGE: Anomaly Detection in Sequences of Attributed Graph Edges applied to insider threat detection at fine-grained level

2020-07-14 · Mathieu Garchery, Michael Granitzer

Previous works on the CERT insider threat detection case have neglected graph and text features despite their relevance to describe user behavior. Additionally, existing systems heavily rely on feature engineering and au…

Anomaly DetectionFeature Engineering

Chimera: Harnessing Multi-Agent LLMs for Automatic Insider Threat Simulation

2025-08-11 · Jiongchi Yu, Xiaofei Xie, Qiang Hu, Yuhan Ma 외 arxiv

Insider threats pose a persistent and critical security risk, yet are notoriously difficult to detect in complex enterprise environments, where malicious actions are often hidden within seemingly benign user behaviors. A…

AI-Driven IRM: Transforming insider risk management with adaptive scoring and LLM-based threat detection

2025-05-01 · Lokesh Koli, Shubham Kalra, Rohan Thakur, Anas Saifi 외

Insider threats pose a significant challenge to organizational security, often evading traditional rule-based detection systems due to their subtlety and contextual nature. This paper presents an AI-powered Insider Risk …

Anomaly DetectionFederated LearningManagement

Scalable and Ethical Insider Threat Detection through Data Synthesis and Analysis by LLMs

2025-02-10 · Haywood Gelman, John D. Hastings

Insider threats wield an outsized influence on organizations, disproportionate to their small numbers. This is due to the internal access insiders have to systems, information, and infrastructure. %One example of this in…

DiversitySynthetic Data Generation

Strategic Informed Trading and the Value of Private Information

2024-04-12 · Michail Anthropelos, Scott Robertson

We consider a market of risky financial assets whose participants are an informed trader, a representative uninformed trader, and noisy liquidity providers. We prove the existence of a market-clearing equilibrium when th…