Insider threats pose a significant and complex challenge to organizations, often causing more damage than external threats. Conventional methods primarily focus on analyzing sequences of user behavior to identify malicious activities, yet they frequently fail to fully expose the intricate details of potential insider threats. This research introduces the User and Entity Behavior Analysis (UEBA) approach, which aims to conduct a thorough analysis of user audit data from both the perspectives of behavior sequences and behavior features to enhance the identification of internal risks. This approach integrates the Adaptive Synthetic Sampling (ADASYN) algorithm to address data imbalance issues. Furthermore, it leverages a hybrid model that combines attention-based Bi-LSTM with ResNet designed for image classification to execute feature extraction. This method efficiently captures essential information crucial for the detection of insider threats. Our comparative experiments on the CERT dataset r4.2 show that our model achieves an F1-score of up to 0.9752 in daily-level insider threat detection, outperforming existing baselines, demonstrating the effectiveness of our method.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Insider Threat Detection Based on User and Entity Behavior Analysis with a Hybrid Model

  • Yue Song,
  • Jianting Yuan

摘要

Insider threats pose a significant and complex challenge to organizations, often causing more damage than external threats. Conventional methods primarily focus on analyzing sequences of user behavior to identify malicious activities, yet they frequently fail to fully expose the intricate details of potential insider threats. This research introduces the User and Entity Behavior Analysis (UEBA) approach, which aims to conduct a thorough analysis of user audit data from both the perspectives of behavior sequences and behavior features to enhance the identification of internal risks. This approach integrates the Adaptive Synthetic Sampling (ADASYN) algorithm to address data imbalance issues. Furthermore, it leverages a hybrid model that combines attention-based Bi-LSTM with ResNet designed for image classification to execute feature extraction. This method efficiently captures essential information crucial for the detection of insider threats. Our comparative experiments on the CERT dataset r4.2 show that our model achieves an F1-score of up to 0.9752 in daily-level insider threat detection, outperforming existing baselines, demonstrating the effectiveness of our method.