<p>Detecting insider threats is a critical challenge for organizations due to their potential to cause substantial financial and reputational harm. This study explores the effectiveness of two feature representation approaches, vector-based (VecRep) and image-based (ImgRep), in detecting insider threats using various deep learning (DL) and machine learning (ML) models. The study uses the Carnegie Mellon University CERT benchmark dataset, which provides realistic simulations of insider threat scenarios. VecRep captures activity-based numerical data but may miss complex behavioral patterns crucial for detecting subtle threats. ImgRep, on the other hand, transforms user activity into image representations, enabling the analysis of intricate patterns within user behavior. Our findings demonstrate that ImgRep, especially when paired with DL models, significantly outperforms VecRep in terms of accuracy, F1 score, and AUC score, showing greater robustness in handling high-dimensional data. Furthermore, this study provides the first comparative analysis of VecRep and ImgRep for insider threat detection, offering practical insights for researchers and practitioners. These insights include implications for the choice of feature representation techniques, model selection, and system scalability. Results indicate that ImgRep holds substantial promise for improving insider threat detection systems, as it effectively addresses some limitations of VecRep in capturing complex patterns. This research contributes to the field by underscoring the potential of ImgRep in cybersecurity and by identifying avenues for future work, such as enhancing data resolution and conducting further statistical validation to confirm these findings.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Cyber insights: exploring the effectiveness of image-based and vector-based feature representations in insider threat detection

  • Krunal Dhanraj Randive,
  • R. Mohan,
  • Ambairam Muthu Sivakrishna

摘要

Detecting insider threats is a critical challenge for organizations due to their potential to cause substantial financial and reputational harm. This study explores the effectiveness of two feature representation approaches, vector-based (VecRep) and image-based (ImgRep), in detecting insider threats using various deep learning (DL) and machine learning (ML) models. The study uses the Carnegie Mellon University CERT benchmark dataset, which provides realistic simulations of insider threat scenarios. VecRep captures activity-based numerical data but may miss complex behavioral patterns crucial for detecting subtle threats. ImgRep, on the other hand, transforms user activity into image representations, enabling the analysis of intricate patterns within user behavior. Our findings demonstrate that ImgRep, especially when paired with DL models, significantly outperforms VecRep in terms of accuracy, F1 score, and AUC score, showing greater robustness in handling high-dimensional data. Furthermore, this study provides the first comparative analysis of VecRep and ImgRep for insider threat detection, offering practical insights for researchers and practitioners. These insights include implications for the choice of feature representation techniques, model selection, and system scalability. Results indicate that ImgRep holds substantial promise for improving insider threat detection systems, as it effectively addresses some limitations of VecRep in capturing complex patterns. This research contributes to the field by underscoring the potential of ImgRep in cybersecurity and by identifying avenues for future work, such as enhancing data resolution and conducting further statistical validation to confirm these findings.