Detecting Unknown Insider Threat Scenarios

IEEE Symposium on Security and Privacy Workshops(2014)

引用 49|浏览66
暂无评分
摘要
This paper reports results from a set of experiments that evaluate an insider threat detection prototype on its ability to detect scenarios that have not previously been seen or contemplated by the developers of the system. We show the ability to detect a large variety of insider threat scenario instances imbedded in real data with no prior knowledge of what scenarios are present or when they occur. We report results of an ensemble-based, unsupervised technique for detecting potential insider threat instances over eight months of real monitored computer usage activity augmented with independently developed, unknown but realistic, insider threat scenarios that robustly achieves results within 5% of the best individual detectors identified after the fact. We explore factors that contribute to the success of the ensemble method, such as the number and variety of unsupervised detectors and the use of prior knowledge encoded in scenario-based detectors designed for known activity patterns. We report results over the entire period of the ensemble approach and of ablation experiments that remove the scenario-based detectors.
更多
查看译文
关键词
security of data,ablation experiments,ensemble method,ensemble-based unsupervised technique,insider threat detection prototype,potential insider threat instances,real monitored computer usage activity,scenario-based detectors,anomaly detection,experimental case study,insider threat,unsupervised ensembles
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要