Applying One-Class Algorithms for Data Stream-Based Insider Threat Detection

被引:5
|
作者
Peccatiello, Rafael Bruno [1 ]
Gondim, Joao Jose Costa [1 ]
Garcia, Luis Paulo Faina [1 ]
机构
[1] Univ Brasilia, Dept Comp Sci, BR-70910900 Brasilia, Brazil
关键词
Insider threat detection; data stream; machine learning; one-class classification; CLASSIFICATION; NETWORK;
D O I
10.1109/ACCESS.2023.3293825
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
An insider threat is anyone who has legitimate access to a particular organization's network and uses that access to harm that organization. Insider threats may act with or without intent, but when they have an intention, they usually also have some specific motivation. This motivation can vary, including but not limited to personal discontent, financial issues, and coercion. It is hard to face insider threats with traditional security solutions because those solutions are limited to the signature detection paradigm. To overcome this restriction, researchers have proposed using Machine Learning which can address Insider Threat issues more comprehensively. Some of them have used batch learning, and others have used stream learning. Batch approaches are simpler to implement, but the problem is how to apply them in the real world. That is because real insider threat scenarios have complex characteristics to address by batch learning. Although more complex, stream approaches are more comprehensive and feasible to implement. Some studies have also used unsupervised and supervised Machine Learning techniques, but obtaining labeled samples makes it hard to implement fully supervised solutions. This study proposes a framework that combines different data science techniques to address insider threat detection. Among them are using semi-supervised and supervised machine learning, data stream analysis, and periodic retraining procedures. The algorithms used in the implementation were Isolation Forest, Elliptic Envelop, and Local Outlier Factor. This study evaluated the results according to the values obtained by the precision, recall, and F1-Score metrics. The best results were obtained by the ISOF algorithm, with 0.78 for the positive class (malign) recall and 0.80 for the negative class (benign) recall.
引用
收藏
页码:70560 / 70573
页数:14
相关论文
共 50 条
  • [41] One-class classification - From theory to practice: A case-study in radioactive threat detection
    Bellinger, Colin
    Sharma, Shiven
    Japkowicz, Nathalie
    EXPERT SYSTEMS WITH APPLICATIONS, 2018, 108 : 223 - 232
  • [42] Optimization Algorithms for One-Class Classification Ensemble Pruning
    Krawczyk, Bartosz
    Wozniak, Michal
    INTELLIGENT INFORMATION AND DATABASE SYSTEMS, PT II, 2014, 8398 : 127 - 136
  • [43] Robust ranking algorithms for one-class collaborative filtering
    School of Information Science and Technology, Sun Yat-Sen University, Guangzhou
    510006, China
    不详
    528333, China
    不详
    510275, China
    Zidonghua Xuebao Acta Auto. Sin., 2 (405-418):
  • [44] End-to-End Deep One-Class Learning for Anomaly Detection in UAV Video Stream
    Hamdi, Slim
    Bouindour, Samir
    Snoussi, Hichem
    Wang, Tian
    Abid, Mohamed
    JOURNAL OF IMAGING, 2021, 7 (05)
  • [45] Stream-Based Visually Lossless Data Compression Applying Variable Bit-Length ADPCM Encoding
    Yamagiwa, Shinichi
    Ichinomiya, Yuma
    SENSORS, 2021, 21 (13)
  • [46] One-class classification for oil spill detection
    Gambardella, Attilio
    Giacinto, Giorgio
    Migliaccio, Maurizio
    Montali, Andrea
    PATTERN ANALYSIS AND APPLICATIONS, 2010, 13 (03) : 349 - 366
  • [47] Improving one-class SVM for anomaly detection
    Li, KL
    Huang, HK
    Tian, SF
    Xu, W
    2003 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-5, PROCEEDINGS, 2003, : 3077 - 3081
  • [48] Applying discriminant functions with one-class SVMS for multi-class classification
    Lee, Zhi-Ying
    Yeh, Chi-Yuan
    Lee, Shie-Jue
    PROCEEDINGS OF 2007 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2007, : 1954 - 1959
  • [49] Incremental one-class classification on stationary data stream using two-quarter sphere
    Ghomanjani, Mohammad Hadi
    Hamidzadeh, Javad
    EXPERT SYSTEMS, 2018, 35 (05)
  • [50] One-class strategies for security information detection
    Tao, Qing
    Wu, Gao-Wei
    Wang, Jue
    INTELLIGENCE AND SECURITY INFORMATICS, PROCEEDINGS, 2006, 3917 : 171 - 172