An improved feature extraction algorithm for insider threat using hidden Markov model on user behavior detection

被引:11
|
作者
Ye, Xiaoyun [1 ]
Han, Myung-Mook [2 ]
机构
[1] Gachon Univ, Dept Comp Sci, Seongnam, South Korea
[2] Gachon Univ, Dept Software, Seongnam, South Korea
基金
新加坡国家研究基金会;
关键词
Hidden Markov model; Insider threat detection; Viterbi algorithm; Anomaly detection;
D O I
10.1108/ICS-12-2019-0142
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose By using a new feature extraction method on the Cert data set and using a hidden Markov model (HMM) to model and analyze the behavior of users to distinguish whether the behavior is normal within a continuous period. Design/methodology/approach Feature extraction of five parts of the time series by rules and sorting in chronological order. Use the obtained features to calculate the probability parameters required by the HMM model and establish a behavior model for each user. When the user has abnormal behavior, the model will return a very low probability value to distinguish between normal and abnormal information. Findings Generally, HMM parameters are obtained by supervised learning and unsupervised learning, but the hidden state cannot be clearly defined. When the hidden state is determined according to the data set, the accuracy of the model will be improved. Originality/value This paper proposes a new feature extraction method and analysis mode, which determines the shape of the hidden state according to the situation of the data set, making subsequent HMM modeling simple and efficient and in turn improving the accuracy of user behavior detection.
引用
收藏
页码:19 / 36
页数:18
相关论文
共 50 条
  • [41] Text Information Extraction based on Genetic Algorithm and Hidden Markov Model
    Li, Rong
    Zheng, Jia-heng
    Pei, Chun-qin
    PROCEEDINGS OF THE FIRST INTERNATIONAL WORKSHOP ON EDUCATION TECHNOLOGY AND COMPUTER SCIENCE, VOL I, 2009, : 334 - +
  • [42] Optimization of hidden Markov model by a genetic algorithm for web information extraction
    Xiao, Jiyi
    Zou, Lamei
    Li, Chuanqi
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS AND KNOWLEDGE ENGINEERING (ISKE 2007), 2007,
  • [43] Dynamic Community Detection Algorithm Based On Hidden Markov Model
    Dong, Zhe
    PROCEEDINGS OF THE 2016 INTERNATIONAL SYMPOSIUM ON ADVANCES IN ELECTRICAL, ELECTRONICS AND COMPUTER ENGINEERING (ISAEECE), 2016, 69 : 288 - 294
  • [44] A Discrete Feature Vector for Endpoint Detection of Speech with Hidden Markov Model
    Lee, Jeiky
    Oh, Chang Hyuck
    KOREAN JOURNAL OF APPLIED STATISTICS, 2008, 21 (06) : 959 - 967
  • [45] Multi-stage intrusion detection system using Hidden Markov Model algorithm
    Lee, Do-hyeon
    Kim, Doo-young
    Jung, Jae-il
    ICISS 2008: INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND SECURITY, PROCEEDINGS, 2008, : 72 - 77
  • [46] Spam Email Detection using ID3 Algorithm and Hidden Markov Model
    Kumar, Vikrant
    Monika
    Kumar, Parveen
    Sharma, Ambalika
    2018 CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY (CICT'18), 2018,
  • [47] Query-by-Example Spoken Term Detection Using Bottleneck Feature and Hidden Markov Model
    Liu, Xue
    Guo, Wu
    Wang, Niansong
    2015 12TH INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS AND KNOWLEDGE DISCOVERY (FSKD), 2015, : 1319 - 1323
  • [48] An Improved QRS Detection Method using Hidden Markov Models
    Belkadi, M. A.
    Daamouche, A.
    2017 6TH INTERNATIONAL CONFERENCE ON SYSTEMS AND CONTROL (ICSC' 17), 2017, : 81 - 84
  • [49] Software Abnormal Behavior Detection Based on Hidden Markov Model
    Zhao, Jingling
    Huang, Guoxiao
    Liu, Tianyu
    Cui, Baojiang
    INNOVATIVE MOBILE AND INTERNET SERVICES IN UBIQUITOUS COMPUTING, IMIS-2017, 2018, 612 : 929 - 940
  • [50] Detection and Location for Network Hidden Threat Information Based on Improved MSCKF Algorithm
    Zhang, Jie
    Sun, Jinguang
    He, Hua
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 127 (01) : 405 - 418