Multi-Domain Information Fusion for Insider Threat Detection

被引:57
|
作者
Eldardiry, Hoda [1 ]
Bart, Evgeniy [1 ]
Liu, Juan [1 ]
Hanley, John [1 ]
Price, Bob [1 ]
Brdiczka, Oliver [1 ]
机构
[1] Xerox Corp, Palo Alto Res Ctr, Palo Alto, CA 94304 USA
关键词
Insider threat detection; anomaly detection; information fusion;
D O I
10.1109/SPW.2013.14
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Malicious insiders pose significant threats to information security, and yet the capability of detecting malicious insiders is very limited. Insider threat detection is known to be a difficult problem, presenting many research challenges. In this paper we report our effort on detecting malicious insiders from large amounts of work practice data. We propose novel approaches to detect two types of insider activities: (1) blend-in anomalies, where malicious insiders try to behave similar to a group they do not belong to, and (2) unusual change anomalies, where malicious insiders exhibit changes in their behavior that are dissimilar to their peers' behavioral changes. Our first contribution focuses on detecting blend-in malicious insiders. We propose a novel approach by examining various activity domains, and detecting behavioral inconsistencies across these domains. Our second contribution is a method for detecting insiders with unusual changes in behavior. The key strength of this proposed approach is that it avoids flagging common changes that can be mistakenly detected by typical temporal anomaly detection mechanisms. Our third contribution is a method that combines anomaly indicators from multiple sources of information.
引用
下载
收藏
页码:45 / 51
页数:7
相关论文
共 50 条
  • [1] Anomaly-Based Insider Threat Detection via Hierarchical Information Fusion
    Wang, Enzhi
    Li, Qicheng
    Zhao, Shiwan
    Han, Xue
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING, ICANN 2023, PT III, 2023, 14256 : 13 - 25
  • [2] Improving Insider Threat Detection Through Multi-Modelling/Data Fusion
    Brown, David P.
    Buede, Dennis
    Vermillion, Sean D.
    17TH ANNUAL CONFERENCE ON SYSTEMS ENGINEERING RESEARCH (CSER), 2019, 153 : 100 - 107
  • [3] Steganalysis of AMR Speech Stream Based on Multi-Domain Information Fusion
    Guo, Chuanpeng
    Yang, Wei
    Huang, Liusheng
    IEEE-ACM TRANSACTIONS ON AUDIO SPEECH AND LANGUAGE PROCESSING, 2024, 32 : 4077 - 4090
  • [4] Exploiting Multi-domain Visual Information for Fake News Detection
    Qi, Peng
    Cao, Juan
    Yang, Tianyun
    Guo, Junbo
    Li, Jintao
    2019 19TH IEEE INTERNATIONAL CONFERENCE ON DATA MINING (ICDM 2019), 2019, : 518 - 527
  • [5] Electricity theft detection method based on multi-domain feature fusion
    Zhao, Hong-shan
    Sun, Cheng-yan
    Ma, Li-bo
    Xue, Yang
    Guo, Xiao-mei
    Chang, Jie-ying
    IET SCIENCE MEASUREMENT & TECHNOLOGY, 2023, 17 (03) : 93 - 104
  • [6] Multi-Source Multi-Domain Data Fusion for Cyberattack Detection in Power Systems
    Sahu, Abhijeet
    Mao, Zeyu
    Wlazlo, Patrick
    Huang, Hao
    Davis, Katherine
    Goulart, Ana
    Zonouz, Saman
    IEEE ACCESS, 2021, 9 : 119118 - 119138
  • [7] Multi-domain Information Fusion for Key-Points Guided GAN Inversion
    Xu, Ruize
    Qiu, Xiaowen
    He, Boan
    Ge, Weifeng
    Zhang, Wenqiang
    PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT XI, 2024, 14435 : 146 - 157
  • [8] Fault diagnosis of blade crack based on multi-domain feature and information fusion
    Ma, Tianchi
    Shen, Junxian
    Song, Di
    Xu, Feiyun
    Dongnan Daxue Xuebao (Ziran Kexue Ban)/Journal of Southeast University (Natural Science Edition), 2024, 54 (06): : 1567 - 1573
  • [9] BEAM: An Anomaly-Based Threat Detection System for Enterprise Multi-Domain Data
    Lin, Derek
    Li, Anying
    Foltz, Ryan
    2020 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2020, : 2610 - 2618
  • [10] A Multi-Perspective Approach to Insider Threat Detection
    Raissi-Dehkordi, Majid
    Carr, David
    2011 - MILCOM 2011 MILITARY COMMUNICATIONS CONFERENCE, 2011, : 1164 - 1169