paper-with-me

Papers

Unsupervised User-Based Insider Threat Detection Using Bayesian Gaussian Mixture Models

2022-11-23 · Simon Bertrand, Nadia Tawbi, Josée Desharnais

Insider threats are a growing concern for organizations due to the amount of damage that their members can inflict by combining their privileged access and domain knowledge. Nonetheless, the detection of such threats is challenging, precisely because of the ability of the authorized personnel to easily conduct malicious actions and because of the immense size and diversity of audit data produced by organizations in which the few malicious footprints are hidden. In this paper, we propose an unsupervised insider threat detection system based on audit data using Bayesian Gaussian Mixture Models. The proposed approach leverages a user-based model to optimize specific behaviors modelization and an automatic feature extraction system based on Word2Vec for ease of use in a real-life scenario. The solution distinguishes itself by not requiring data balancing nor to be trained only on normal instances, and by its little domain knowledge required to implement. Still, results indicate that the proposed method competes with state-of-the-art approaches, presenting a good recall of 88\%, accuracy and true negative rate of 93%, and a false positive rate of 6.9%. For our experiments, we used the benchmark dataset CERT version 4.2.

📄 PDF Abstract BibTeX arXiv:2211.14437

Code (0)

등록된 구현이 없습니다.

Tasks

Diversity

Similar Papers 제목 키워드 기반

Deep Learning for Unsupervised Insider Threat Detection in Structured Cybersecurity Data Streams

2017-10-02 · Aaron Tuor, Samuel Kaplan, Brian Hutchinson, Nicole Nichols 외

Analysis of an organization's computer network activity is a key component of early detection and mitigation of insider threat, a growing concern for many organizations. Raw system logs are a prototypical example of stre…

Anomaly Detection

Insider Threat Detection Based on Stress Recognition Using Keystroke Dynamics

2020-05-06 · Azamat Sultanov, Konstantin Kogos

Insider threat is one of the most pressing threats in the field of information security as it leads to huge financial losses by the companies. Most of the proposed methods for detecting this threat require expensive and …

Deep Learning for Insider Threat Detection: Review, Challenges and Opportunities

2020-05-25 · Shuhan Yuan, Xintao Wu

Insider threats, as one type of the most challenging threats in cyberspace, usually cause significant loss to organizations. While the problem of insider threat detection has been studied for a long time in both security…

BIG-bench Machine LearningDeep LearningFeature Engineering

RMSL: Weakly-Supervised Insider Threat Detection with Robust Multi-sphere Learning

2025-08-15 · Yang Wang, Yaxin Zhao, Xinyu Jiao, Sihan Xu 외 arxiv

Insider threat detection aims to identify malicious user behavior by analyzing logs that record user interactions. Due to the lack of fine-grained behavior-level annotations, detecting specific behavior-level anomalies w…

Multiple Instance Learning

Attention to Patterns is all you need for Insider threat detection

2024-10-26 · International Conference on Artificial Intelligence, Metaverse and Cybersecurity (ICAMAC) 2024 10 · Priya Tiwary, Akshayraj Madhubalan, Amit Gautam, Raj Darji

Insider threats pose a significant and often underestimated risk to organizations. Traditional anomaly detection methods relying on simplistic patterns and lacking temporal awareness struggle to capture the nuances of us…

AllAnomaly DetectionClassification