This paper deals with the problem of analyzing data collected from physical access control systems (PACS), and, in particular, tasks of processing datasets, describing and classifying user behavior scenarios, computing and representing results. Nowadays issues related to PACS data analysis are still relatively unexplored. The collected data, both structured and unstructured, are often underutilized, but they can be used for practical purpose to uncover unusual or anomalous user activities that might signal security risks within the protected perimeter. In previous works we proposed some methods of user behavior analysis and anomaly detection on the basis of event data. To enhance these results and automate data processing, we propose a simple software framework that simplifies configuring, processing and visualizing PACS events. Several modes of data analysis and visualization are considered, and vector graphs are built to represent the user profiles. Application of clustering to such vectors allows us to group profiles united by similar behavior models. Directions for future research include using methods of clustering and machine learning to enhance anomaly detection and identification security threats with complex patterns, including previously unknown ones, more accurately. This can advance the capabilities of PACS analytics, providing more comprehensive, accurate, and actionable insights into user behavior and corporate security.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Framework for User Behavior Analytics in Physical Access Control Systems

  • Anna Motienko,
  • Elena Evnevich,
  • Mikhail Vinogradov,
  • Dmitriy Levonevskiy

摘要

This paper deals with the problem of analyzing data collected from physical access control systems (PACS), and, in particular, tasks of processing datasets, describing and classifying user behavior scenarios, computing and representing results. Nowadays issues related to PACS data analysis are still relatively unexplored. The collected data, both structured and unstructured, are often underutilized, but they can be used for practical purpose to uncover unusual or anomalous user activities that might signal security risks within the protected perimeter. In previous works we proposed some methods of user behavior analysis and anomaly detection on the basis of event data. To enhance these results and automate data processing, we propose a simple software framework that simplifies configuring, processing and visualizing PACS events. Several modes of data analysis and visualization are considered, and vector graphs are built to represent the user profiles. Application of clustering to such vectors allows us to group profiles united by similar behavior models. Directions for future research include using methods of clustering and machine learning to enhance anomaly detection and identification security threats with complex patterns, including previously unknown ones, more accurately. This can advance the capabilities of PACS analytics, providing more comprehensive, accurate, and actionable insights into user behavior and corporate security.