Unsupervised User-Based Insider Threat Detection Using Bayesian Gaussian Mixture Models

被引:0
|
作者
Bertrand, Simon [1 ]
Desharnais, Josee [1 ]
Tawbi, Nadia [1 ]
机构
[1] Laval Univ, Informat & Genie Logiciel, Quebec City, PQ, Canada
关键词
Insider Threat; Bayesian Gaussian Mixture Model; Gaussian Mixture Model; Unsupervised learning; Word2Vec;
D O I
10.1109/PST58708.2023.10320169
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Insider threats are a growing concern for organizations due to the amount of damage that their members can inflict by combining their privileged access and domain knowledge. Nonetheless, the detection of such threats is challenging, precisely because of the ability of the authorized personnel to easily conduct malicious actions and because of the immense size and diversity of audit data produced by organizations in which the few malicious footprints are hidden. In this paper, we propose an unsupervised insider threat detection system based on audit data using Bayesian Gaussian Mixture Models. The proposed approach leverages a user-based model to optimize specific behaviors modelization and an automatic feature extraction system based on Word2Vec for ease of use in a real-life scenario. The solution distinguishes itself by not requiring data balancing nor to be trained only on normal instances, and by its little domain knowledge required to implement. Still, results indicate that the proposed method competes with state-of-the-art approaches that use stronger hypotheses, presenting a good recall of 88%, accuracy and true negative rate of 93%, and a false positive rate of 6.9%. For our experiments, we used the benchmark dataset CERT version 4.2.
引用
收藏
页码:52 / 61
页数:10
相关论文
共 50 条
  • [21] Study on user behavior profiling in insider threat detection
    Guo Y.
    Liu C.
    Kong J.
    Wang Y.
    2018, Editorial Board of Journal on Communications (39): : 141 - 150
  • [22] A Trust Aware Unsupervised Learning Approach for Insider Threat Detection
    Aldairi, Maryam
    Karimi, Leila
    Joshi, James
    2019 IEEE 20TH INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION FOR DATA SCIENCE (IRI 2019), 2019, : 89 - 98
  • [23] Anchored Bayesian Gaussian mixture models
    Kunkel, Deborah
    Peruggia, Mario
    ELECTRONIC JOURNAL OF STATISTICS, 2020, 14 (02): : 3869 - 3913
  • [24] DEEP BAYESIAN UNSUPERVISED SOURCE SEPARATION BASED ON A COMPLEX GAUSSIAN MIXTURE MODEL
    Bando, Yoshiaki
    Sasaki, Yoko
    Yoshii, Kazuyoshi
    2019 IEEE 29TH INTERNATIONAL WORKSHOP ON MACHINE LEARNING FOR SIGNAL PROCESSING (MLSP), 2019,
  • [25] Insider Threat Detection Based on User and Entity Behavior Analysis with a Hybrid Model
    Song, Yue
    Yuan, Jianting
    INFORMATION SECURITY, PT II, ISC 2024, 2025, 15258 : 323 - 340
  • [26] Insights into user behavioral-based insider threat detection: systematic review
    Kamatchi, K.
    Uma, E.
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2025, 24 (02)
  • [27] AUTH: An Adversarial Autoencoder Based Unsupervised Insider Threat Detection Scheme for Multisource Logs
    Zhu, Xingjian
    Dong, Jiankuo
    Qi, Jin
    Zhou, Zhenguo
    Dong, Zhenjiang
    Sun, Yanfei
    Wang, Moyu
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2024, 20 (09) : 10954 - 10965
  • [28] Gaussian Mixture Models for Affordance Learning using Bayesian Networks
    Osorio, Pedro
    Bernardino, Alexandre
    Martinez-Cantin, Ruben
    Santos-Victor, Jose
    IEEE/RSJ 2010 INTERNATIONAL CONFERENCE ON INTELLIGENT ROBOTS AND SYSTEMS (IROS 2010), 2010,
  • [29] Insider threat prediction based on unsupervised anomaly detection scheme for proactive forensic investigation
    Wei, Yichen
    Chow, Kam-Pui
    Yiu, Siu-Ming
    FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, 2021, 38
  • [30] On particle dispersion statistics using unsupervised learning and Gaussian mixture models
    Christakis, Nicholas
    Drikakis, Dimitris
    PHYSICS OF FLUIDS, 2024, 36 (09)