Robust Anomaly-Based Insider Threat Detection Using Graph Neural Network

被引:3
|
作者
Xiao, Junchao [1 ]
Yang, Lin [2 ]
Zhong, Fuli [1 ]
Wang, Xiaolei [2 ]
Chen, Hongbo [1 ]
Li, Dongyang [3 ]
机构
[1] Sun Yat Sen Univ, Sch Syst Sci & Engn, Guangzhou 510006, Peoples R China
[2] Chinese Acad Mil Sci, Inst Syst Engn, Natl Key Lab Sci & Technol Informat Syst Secur, Beijing 100039, Peoples R China
[3] Army Engn Univ PLA, Command & Control Engn Coll, Nanjing 211101, Peoples R China
基金
中国国家自然科学基金;
关键词
Anomaly detection; insider threat; graph neural network;
D O I
10.1109/TNSM.2022.3222635
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Misuse or malicious access to critical assets of information systems by insiders usually causes significant loss to organizations. The issue of insider threat detection for information systems has received many researchers' attention in both security and data mining fields, and a lot of related research results were presented. However, there are still many challenges in capturing the behavior difference between malicious insiders and normal users accurately, such as lack of labeled insider threats, the subtle and adaptive nature of insider threats, complexity, heterogeneity, sparsity of the underlying data, etc. To detect insider threats with large and complex audit data, a Multi-Edge Weight Relational Graph Neural Network method (MEWRGNN) for robust anomaly detection is proposed in this paper. Unlike most existing approaches, the MEWRGNN adopts several graph neural networks to capture the contextual relationship of user behaviors over a period of time, which is a critical factor for achieving accurate anomaly identification. The MEWRGNN achieves a certain degree of interpretability through ranking the contribution of different edge-representation features. Evaluation experimental results demonstrate that the MEWRGNN can learn a model from limited sample data sets, and achieve quick and accurate insider threat detection performance. In addition, other feature ranking results allow providing security analysts with understandable insights for investigating the detected insider threats.
引用
收藏
页码:3717 / 3733
页数:17
相关论文
共 50 条
  • [1] Anomaly-based Insider Threat Detection using Deep Autoencoders
    Liu, Liu
    De Vel, Olivier
    Chen, Chao
    Zhang, Jun
    Xiang, Yang
    [J]. 2018 18TH IEEE INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS (ICDMW), 2018, : 39 - 48
  • [2] Insider Threat Detection Model Using Anomaly-Based Isolation Forest Algorithm
    Al-Shehari, Taher
    Al-Razgan, Muna
    Alfakih, Taha
    Alsowail, Rakan A.
    Pandiaraj, Saravanan
    [J]. IEEE ACCESS, 2023, 11 : 118170 - 118185
  • [3] Robust anomaly-based intrusion detection system for in-vehicle network by graph neural network framework
    Junchao Xiao
    Lin Yang
    Fuli Zhong
    Hongbo Chen
    Xiangxue Li
    [J]. Applied Intelligence, 2023, 53 : 3183 - 3206
  • [4] Robust anomaly-based intrusion detection system for in-vehicle network by graph neural network framework
    Xiao, Junchao
    Yang, Lin
    Zhong, Fuli
    Chen, Hongbo
    Li, Xiangxue
    [J]. APPLIED INTELLIGENCE, 2023, 53 (03) : 3183 - 3206
  • [5] Anomaly-Based Insider Threat Detection via Hierarchical Information Fusion
    Wang, Enzhi
    Li, Qicheng
    Zhao, Shiwan
    Han, Xue
    [J]. ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING, ICANN 2023, PT III, 2023, 14256 : 13 - 25
  • [6] A Graph Convolution Neural Network Based Method for Insider Threat Detection
    Fei, Kexiong
    Zhou, Jiang
    Su, Lin
    Wang, Weiping
    Chen, Yong
    Zhang, Fan
    [J]. 2022 IEEE INTL CONF ON PARALLEL & DISTRIBUTED PROCESSING WITH APPLICATIONS, BIG DATA & CLOUD COMPUTING, SUSTAINABLE COMPUTING & COMMUNICATIONS, SOCIAL COMPUTING & NETWORKING, ISPA/BDCLOUD/SOCIALCOM/SUSTAINCOM, 2022, : 66 - 73
  • [7] A Convolutional Neural Network for Improved Anomaly-Based Network Intrusion Detection
    Al-Turaiki, Isra
    Altwaijry, Najwa
    [J]. BIG DATA, 2021, 9 (03) : 233 - 252
  • [8] Anomaly Detection with Graph Convolutional Networks for Insider Threat and Fraud Detection
    Jiang, Jianguo
    Chen, Jiuming
    Gu, Tianbo
    Choo, Kim-Kwang Raymond
    Liu, Chao
    Yu, Min
    Huang, Weiqing
    Mohapatra, Prasant
    [J]. MILCOM 2019 - 2019 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2019,
  • [9] Network Anomaly Detection Using a Graph Neural Network
    Kisanga, Patrice
    Woungang, Isaac
    Traore, Issa
    Carvalho, Glaucio H. S.
    [J]. 2023 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2023, : 61 - 65
  • [10] Anomaly-Based Network Intrusion Detection Using SVM
    Zhang, Yuan
    Yang, Qinghai
    Lambotharan, Sangarapillai
    Kyriakopoulos, Konstantinos
    Ghafir, Ibrahim
    AsSadhan, Basil
    [J]. 2019 11TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS AND SIGNAL PROCESSING (WCSP), 2019,