Insider Threat Detection Based on Deep Clustering of Multi-Source Behavioral Events

被引:5
|
作者
Wang, Jiarong [1 ]
Sun, Qianran [1 ]
Zhou, Caiqiu [1 ]
机构
[1] Chinese Acad Sci, Inst High Energy Phys, Beijing 100049, Peoples R China
来源
APPLIED SCIENCES-BASEL | 2023年 / 13卷 / 24期
基金
中国国家自然科学基金;
关键词
insider threat; multi-source user behaviors; deep clustering;
D O I
10.3390/app132413021
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
With the continuous advancement of enterprise digitization, insider threats have become one of the primary cybersecurity concerns for organizations. Therefore, it is of great significance to develop an effective insider threat detection mechanism to ensure the security of enterprises. Most methods rely on artificial feature engineering and input the extracted user behavior features into a clustering-based unsupervised machine learning model for insider threat detection. However, feature extraction is independent of clustering-based unsupervised machine learning. As a result, user behavior features are not the most appropriate for clustering-based unsupervised machine learning, and thus, they reduce the insider threat detection accuracy. This paper proposes an insider threat detection method based on the deep clustering of multi-source behavioral events. On the one hand, the proposed method constructs an end-to-end deep clustering network and automatically learns the user behavior feature expression from multi-source behavioral event sequences. On the other hand, a deep clustering objective function is presented to jointly optimize the learning of feature representations and the clustering task for insider threat detection. This optimization can adjust the optimal user behavior features for the clustering model to improve the insider threat detection accuracy. The experimental results show that the proposed end-to-end insider threat detection model can accurately identify insider threats based on abnormal multi-source user behaviors in enterprise networks.
引用
收藏
页数:17
相关论文
共 50 条
  • [31] A Malware Threat Decision Model Based on Dynamic Multi-Source Data Acquisition
    Sun, Di
    Pang, Jian-min
    Dai, Chao
    INTERNATIONAL CONFERENCE ON COMPUTER, NETWORK SECURITY AND COMMUNICATION ENGINEERING (CNSCE 2014), 2014, : 21 - 29
  • [32] An Insider Cyber Threat Prediction Mechanism Based on Behavioral Analysis
    Bhavsar, Kaushal
    Trivedi, Bhushan H.
    PROCEEDINGS OF INTERNATIONAL CONFERENCE ON ICT FOR SUSTAINABLE DEVELOPMENT ICT4SD 2015, VOL 2, 2016, 409 : 345 - 353
  • [33] Multi focus and multi-source image fusion based on deep learning model
    Fu, Jie
    Gao, Xin-Ran
    Xu, Min
    Wang, Wenju
    2019 2ND WORLD CONFERENCE ON MECHANICAL ENGINEERING AND INTELLIGENT MANUFACTURING (WCMEIM 2019), 2019, : 512 - 515
  • [34] Multi-Domain Information Fusion for Insider Threat Detection
    Eldardiry, Hoda
    Bart, Evgeniy
    Liu, Juan
    Hanley, John
    Price, Bob
    Brdiczka, Oliver
    IEEE CS SECURITY AND PRIVACY WORKSHOPS (SPW 2013), 2013, : 45 - 51
  • [35] Multi-source localization on complex networks based on community detection
    Yuan, Shunjie
    Liu, Wenyu
    Zeng, Hefeng
    Wang, Chao
    EPL, 2023, 141 (06)
  • [36] Multi-source detection based on neighborhood entropy in social networks
    Liu, YanXia
    Li, WeiMin
    Yang, Chao
    Wang, JianJia
    SCIENTIFIC REPORTS, 2022, 12 (01)
  • [37] Multi-source detection based on neighborhood entropy in social networks
    YanXia Liu
    WeiMin Li
    Chao Yang
    JianJia Wang
    Scientific Reports, 12
  • [38] Multi-Source Stego Detection with Low-Dimensional Textural Feature and Clustering Ensembles
    Li, Fengyong
    Wu, Kui
    Zhang, Xinpeng
    Lei, Jingsheng
    Wen, Mi
    SYMMETRY-BASEL, 2018, 10 (05):
  • [39] Phase-based road detection in multi-source images
    Sengupta, SK
    Lopez, AS
    Brase, JM
    Paglieroni, DW
    IGARSS 2004: IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM PROCEEDINGS, VOLS 1-7: SCIENCE FOR SOCIETY: EXPLORING AND MANAGING A CHANGING PLANET, 2004, : 3833 - 3836
  • [40] Fabric defect detection based on multi-source feature fusion
    Liu, Zhoufeng
    Liu, Shanliang
    Li, Chunlei
    Li, Bicao
    INTERNATIONAL JOURNAL OF CLOTHING SCIENCE AND TECHNOLOGY, 2022, 34 (02) : 156 - 177