Existing graph-based insider threat detection models extract complex relationships between different behavioral entities through graph embedding or graph neural network models. However, each of these methods has its own advantages and disadvantages, resulting in unsatisfactory performance. Furthermore, the issue of class imbalance has not been adequately addressed in these approaches. To address the above existing problems, this paper proposes a novel day-level insider threat detection method, called BHGITD (bi-hierarchical graph-based insider threat detection). In this model, we first construct a heterogeneous graph at the level of behavioral operations for each user based on system logs and propose a random wandering algorithm applicable to this heterogeneous graph to extract the embedded representations between different behavioral operations. Then a homogeneous graph at the user-day level is constructed based on the organizational relationships among users, and a graph neural network model is used to mine the spatial representations of user-day behaviors. In addition, in terms of data imbalance, we use a random under-sampling technique and a weighted cross-entropy loss function to enhance the model’s detection ability for malicious samples. The experimental results on the CERT r4.2 dataset show that the recall and F1 score of BHGITD reach up to 99.32% and 97.66% respectively, which significantly outperform previous works.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Bi-hierarchical Graph Based Approach for Insider Threat Detection

  • Rui Hou,
  • Xiaolong Deng

摘要

Existing graph-based insider threat detection models extract complex relationships between different behavioral entities through graph embedding or graph neural network models. However, each of these methods has its own advantages and disadvantages, resulting in unsatisfactory performance. Furthermore, the issue of class imbalance has not been adequately addressed in these approaches. To address the above existing problems, this paper proposes a novel day-level insider threat detection method, called BHGITD (bi-hierarchical graph-based insider threat detection). In this model, we first construct a heterogeneous graph at the level of behavioral operations for each user based on system logs and propose a random wandering algorithm applicable to this heterogeneous graph to extract the embedded representations between different behavioral operations. Then a homogeneous graph at the user-day level is constructed based on the organizational relationships among users, and a graph neural network model is used to mine the spatial representations of user-day behaviors. In addition, in terms of data imbalance, we use a random under-sampling technique and a weighted cross-entropy loss function to enhance the model’s detection ability for malicious samples. The experimental results on the CERT r4.2 dataset show that the recall and F1 score of BHGITD reach up to 99.32% and 97.66% respectively, which significantly outperform previous works.