An improved feature extraction algorithm for insider threat using hidden Markov model on user behavior detection

被引:11
|
作者
Ye, Xiaoyun [1 ]
Han, Myung-Mook [2 ]
机构
[1] Gachon Univ, Dept Comp Sci, Seongnam, South Korea
[2] Gachon Univ, Dept Software, Seongnam, South Korea
基金
新加坡国家研究基金会;
关键词
Hidden Markov model; Insider threat detection; Viterbi algorithm; Anomaly detection;
D O I
10.1108/ICS-12-2019-0142
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose By using a new feature extraction method on the Cert data set and using a hidden Markov model (HMM) to model and analyze the behavior of users to distinguish whether the behavior is normal within a continuous period. Design/methodology/approach Feature extraction of five parts of the time series by rules and sorting in chronological order. Use the obtained features to calculate the probability parameters required by the HMM model and establish a behavior model for each user. When the user has abnormal behavior, the model will return a very low probability value to distinguish between normal and abnormal information. Findings Generally, HMM parameters are obtained by supervised learning and unsupervised learning, but the hidden state cannot be clearly defined. When the hidden state is determined according to the data set, the accuracy of the model will be improved. Originality/value This paper proposes a new feature extraction method and analysis mode, which determines the shape of the hidden state according to the situation of the data set, making subsequent HMM modeling simple and efficient and in turn improving the accuracy of user behavior detection.
引用
收藏
页码:19 / 36
页数:18
相关论文
共 50 条
  • [1] Feature Engineering Method Using Double-Layer Hidden Markov Model for Insider Threat Detection
    Ye, Xiaoyun
    Hong, Sung-Sam
    Han, Myung-Mook
    INTERNATIONAL JOURNAL OF FUZZY LOGIC AND INTELLIGENT SYSTEMS, 2020, 20 (01) : 17 - 25
  • [2] User Behavior Profiling using Ensemble Approach for Insider Threat Detection
    Singh, Malvika
    Mehtre, B. M.
    Sangeetha, S.
    2019 5TH IEEE INTERNATIONAL CONFERENCE ON IDENTITY, SECURITY, AND BEHAVIOR ANALYSIS (ISBA 2019), 2019,
  • [3] Study on user behavior profiling in insider threat detection
    Guo Y.
    Liu C.
    Kong J.
    Wang Y.
    2018, Editorial Board of Journal on Communications (39): : 141 - 150
  • [4] Insider Threat Detection Based on User and Entity Behavior Analysis with a Hybrid Model
    Song, Yue
    Yuan, Jianting
    INFORMATION SECURITY, PT II, ISC 2024, 2025, 15258 : 323 - 340
  • [5] User behavior based Insider Threat Detection using a Multi Fuzzy Classifier
    Malvika Singh
    BM Mehtre
    S Sangeetha
    Multimedia Tools and Applications, 2022, 81 : 22953 - 22983
  • [6] User behavior based Insider Threat Detection using a Multi Fuzzy Classifier
    Singh, Malvika
    Mehtre, B. M.
    Sangeetha, S.
    MULTIMEDIA TOOLS AND APPLICATIONS, 2022, 81 (16) : 22953 - 22983
  • [7] An Insider Threat Detection Method Based on User Behavior Analysis
    Jiang, Wei
    Tian, Yuan
    Liu, Weixin
    Liu, Wenmao
    INTELLIGENT INFORMATION PROCESSING IX, 2018, 538 : 421 - 429
  • [8] Analytical method of web user behavior using Hidden Markov Model
    Kawazu, Hirotaka
    Toriumi, Fujio
    Takano, Masanori
    Wada, Kazuya
    Eukuda, Ichiro
    2016 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2016, : 2518 - 2524
  • [9] Insider Threat Detection Based on User Behavior Modeling and Anomaly Detection Algorithms
    Kim, Junhong
    Park, Minsik
    Kim, Haedong
    Cho, Suhyoun
    Kang, Pilsung
    APPLIED SCIENCES-BASEL, 2019, 9 (19):
  • [10] Semantic feature extraction with multidimensional hidden Markov model
    Jiten, J
    Merialdo, B
    Huet, B
    MULTIMEDIA CONTENT ANALYSIS, MANAGEMENT, AND RETRIEVAL 2006, 2006, 6073