An Artificial Neural Network Autoencoder for Insider Cyber Security Threat Detection

被引:7
|
作者
Saminathan, Karthikeyan [1 ]
Mulka, Sai Tharun Reddy [2 ]
Damodharan, Sangeetha [3 ]
Maheswar, Rajagopal [4 ]
Lorincz, Josip [5 ]
机构
[1] KPR Inst Engn & Technol, Comp Sci & Engn AIML, Coimbatore 641407, Tamil Nadu, India
[2] VIT AP Univ, Comp Sci & Engn, Amaravati 522241, Andhra Pradesh, India
[3] Anna Univ, Madras Inst Technol, Informat Technol, Chennai, Tamil Nadu, India
[4] KPR Inst Engn & Technol, Ctr IoT & AI CITI, Dept ECE, Coimbatore 641407, Tamil Nadu, India
[5] Univ Split, Fac Elect Engn Mech Engn & Naval Architecture FESB, Rudjera Boskovca 32, Split 21000, Croatia
关键词
insider; threat; detection; autoencoder; artificial neural network; cyber security;
D O I
10.3390/fi15120373
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The COVID-19 pandemic made all organizations and enterprises work on cloud platforms from home, which greatly facilitates cyberattacks. Employees who work remotely and use cloud-based platforms are chosen as targets for cyberattacks. For that reason, cyber security is a more concerning issue and is now incorporated into almost every smart gadget and has become a prerequisite in every software product and service. There are various mitigations for external cyber security attacks, but hardly any for insider security threats, as they are difficult to detect and mitigate. Thus, insider cyber security threat detection has become a serious concern in recent years. Hence, this paper proposes an unsupervised deep learning approach that employs an artificial neural network (ANN)-based autoencoder to detect anomalies in an insider cyber security attack scenario. The proposed approach analyzes the behavior of the patterns of users and machines for anomalies and sends an alert based on a set security threshold. The threshold value set for security detection is calculated based on reconstruction errors that are obtained through testing the normal data. When the proposed model reconstructs the user behavior without generating sufficient reconstruction errors, i.e., no more than the threshold, the user is flagged as normal; otherwise, it is flagged as a security intruder. The proposed approach performed well, with an accuracy of 94.3% for security threat detection, a false positive rate of 11.1%, and a precision of 89.1%. From the obtained experimental results, it was found that the proposed method for insider security threat detection outperforms the existing methods in terms of performance reliability, due to implementation of ANN-based autoencoder which uses a larger number of features in the process of security threat detection.
引用
收藏
页数:29
相关论文
共 50 条
  • [31] Quantum Neural Network Classification-Based Cyber Threat Detection in Virtual Environment
    Tripathi, Sarvapriya M.
    Upadhyay, Himanshu
    Soni, Jayesh
    2023 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE, CSCI 2023, 2023, : 391 - 396
  • [32] E-Watcher: insider threat monitoring and detection for enhanced security
    Wei, Zhiyuan
    Rauf, Usman
    Mohsen, Fadi
    ANNALS OF TELECOMMUNICATIONS, 2024, 79 (11-12) : 819 - 831
  • [33] A Framework for Data-Driven Physical Security and Insider Threat Detection
    Mavroeidis, Vasileios
    Vishi, Kamer
    Josang, Audun
    2018 IEEE/ACM INTERNATIONAL CONFERENCE ON ADVANCES IN SOCIAL NETWORKS ANALYSIS AND MINING (ASONAM), 2018, : 1108 - 1115
  • [34] ANALYST INTUITION INSPIRED NEURAL NETWORK BASED CYBER SECURITY ANOMALY DETECTION
    Teoh, Teik-Toe
    Nguwi, Yok-Yen
    Elovici, Yuval
    Ng, Wai-Loong
    Thiang, Soon-Yao
    INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2018, 14 (01): : 379 - 386
  • [35] Anomaly Detection for Cyber-Security Based on Convolution Neural Network : A survey
    Alabadi, Montdher
    Celik, Yuksel
    2ND INTERNATIONAL CONGRESS ON HUMAN-COMPUTER INTERACTION, OPTIMIZATION AND ROBOTIC APPLICATIONS (HORA 2020), 2020, : 558 - 571
  • [36] The insider threat to nuclear safety and security
    Healey, Andrew N.
    SECURITY JOURNAL, 2016, 29 (01) : 23 - 38
  • [37] The insider threat to nuclear safety and security
    Andrew N Healey
    Security Journal, 2016, 29 : 23 - 38
  • [38] Temporal Behavior in Network Traffic as a Basis for Insider Threat Detection
    Rajchel, Brett
    Monaco, John, V
    Singh, Gurminder
    Hu, Angela
    Shingleton, Jarrod
    Anderson, Thomas
    2020 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (SSCI), 2020, : 1427 - 1434
  • [39] Explainable artificial intelligence envisioned security mechanism for cyber threat hunting
    Kumar, Pankaj
    Wazid, Mohammad
    Singh, D. P.
    Singh, Jaskaran
    Das, Ashok Kumar
    Park, Youngho
    Rodrigues, Joel J. P. C.
    SECURITY AND PRIVACY, 2023, 6 (06)
  • [40] Machinery Equipment Early Fault Detection Using Artificial Neural Network Based Autoencoder
    Dwiputranto, Teguh Handjojo
    Setiawan, Noor Akhmad
    Aji, Teguh Bharata
    2017 3RD INTERNATIONAL CONFERENCE ON SCIENCE AND TECHNOLOGY - COMPUTER (ICST), 2017, : 66 - 69