错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Detecting Behavioral Anomalies for Cybersecurity

  • Cheng Wang,
  • Hangyu Zhu

摘要

The behavioral anomaly detection (BAD) is expected to solve effectively a variety of security issues by detecting the deviances from normal behavioral patterns of protected agents. We propose a new graph-based behavioral modeling paradigm for BAD problem, named behavioral identification graph (BIG). Under BIG, the behavioral properties and their co-occurrence associations in behavioral data are modeled as the entities and relationships of graph, respectively; furthermore, both behavioral properties and events are vectorized by a devised event-property composite model, and the behavioral patterns of agents are finally represented as a multidimensional spatial distribution of behavioral properties. Consequently, for a behavior, the intensity of its behavioral anomaly can be transformed into the spatial decentrality of its behavioral agent and properties. To the best of our knowledge, this is the first work to improve behavioral modeling for anomaly detection by integrating inter (event-level)- and intra (property-level)-associations of behaviors into a unified graph and space. Our method is validated by four representative security issues, i.e., fraud detection in online payment services, intrusion detection in network communication services, insider threat detection in organizational information systems, and compromise detection in social networking services.