A Data-Driven Evaluation for Insider Threats

被引:8
|
作者
Sun, Yuqing [1 ]
Xu, Haoran [1 ]
Bertino, Elisa [2 ]
Sun, Chao [1 ]
机构
[1] Shandong Univ, Sch Comp Sci & Technol, Jinan, Peoples R China
[2] Purdue Univ, Dept Comp Sci, W Lafayette, IN 47907 USA
基金
中国国家自然科学基金;
关键词
Insider threat; Audit; Behavior analysis;
D O I
10.1007/s41019-016-0009-x
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Insiders are often legal users who are authorized to access system and data. If they misuse their privileges, it would bring great threat to system security. In practice, we could not have any knowledge about fraud pattern in advance, and most malicious behaviors are often in accordance with security rules; thus, it is difficult to predefine regulations for preventing all kinds of frauds. In this paper, we propose a data-driven evaluation model to detect malicious insiders, which audits user behaviors from both parallel and incremental aspects. Users are grouped together according to their positions and responsibilities, based on which the normal pattern is learned. For each user, a routine behavior pattern is also learned for historical assessment. Then, users are evaluated against both group patterns and routine patterns by probabilistic methods. The deviation degree is adopted as an evidence to justify an anomaly. We also recognize the abnormal activities that often make a user behavior much deviate, which can help an administrator revisit security policies or update activity weights in assessment. At last, experiments are performed on several real dataset.
引用
收藏
页码:73 / 85
页数:13
相关论文
共 50 条
  • [41] A Data-driven Metric for Comprehensive Evaluation of Saliency Models
    Li, Jia
    Xia, Changqun
    Song, Yafei
    Fang, Shu
    Chen, Xiaowu
    [J]. 2015 IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV), 2015, : 190 - 198
  • [42] A Data-Driven Approach for Gin Rummy Hand Evaluation
    Truong, Sang T.
    Neller, Todd W.
    [J]. THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2021, 35 : 15647 - 15654
  • [43] AN EVALUATION OF MONGOLIAN DATA-DRIVEN TEXT-TO-SPEECH
    Altangerel, Chagnaa
    Purev, Jaimai
    Yesyenbyek, Kerey
    Hansakunbuntheung, Chatchawarn
    [J]. 2013 INTERNATIONAL CONFERENCE ORIENTAL COCOSDA HELD JOINTLY WITH 2013 CONFERENCE ON ASIAN SPOKEN LANGUAGE RESEARCH AND EVALUATION (O-COCOSDA/CASLRE), 2013,
  • [44] Data-driven Evaluation of Anticipatory Networking in LTE Networks
    Bui, Nicola
    Widmer, Joerg
    [J]. 2017 PROCEEDINGS OF THE 29TH INTERNATIONAL TELETRAFFIC CONGRESS (ITC 29), VOL 1, 2017, : 46 - 54
  • [45] Evaluation of data-driven delivery of implementation supports in education
    Sanetti, Lisa
    Collier-Meek, Melissa
    Luh, Hao-Jan
    [J]. IMPLEMENTATION SCIENCE, 2017, 13
  • [46] Scientific and ethical evaluation of projects in data-driven medicine
    Caliebe, Amke
    Scherag, Andre
    Strech, Daniel
    Mansmann, Ulrich
    [J]. BUNDESGESUNDHEITSBLATT-GESUNDHEITSFORSCHUNG-GESUNDHEITSSCHUTZ, 2019, 62 (06) : 765 - 772
  • [47] A survey of data-driven approach on multimedia QoE evaluation
    Ruochen Huang
    Xin Wei
    Liang Zhou
    Chaoping Lv
    Hao Meng
    Jiefeng Jin
    [J]. Frontiers of Computer Science, 2018, 12 : 1060 - 1075
  • [48] Data-Driven Quantitative Performance Evaluation of Construction Supervisors
    Yang, Cheng
    Lin, Jia-Rui
    Yan, Ke-Xiao
    Deng, Yi-Chuan
    Hu, Zhen-Zhong
    Liu, Cheng
    [J]. BUILDINGS, 2023, 13 (05)
  • [49] A survey of data-driven approach on multimedia QoE evaluation
    Huang, Ruochen
    Wei, Xin
    Zhou, Liang
    Lv, Chaoping
    Meng, Hao
    Jin, Jiefeng
    [J]. FRONTIERS OF COMPUTER SCIENCE, 2018, 12 (06) : 1060 - 1075
  • [50] Data-Driven Evaluation and Optimisation of Livelihood Improvement Efficiency
    Luo, Muchen
    Wu, Yimin
    [J]. SUSTAINABILITY, 2022, 14 (13)