Using Dirichlet Marked Hawkes Processes for Insider Threat Detection
Using Dirichlet Marked Hawkes Processes for Insider Threat Detection
复制标题
使用狄利克雷标记霍克斯过程进行内部威胁检测
DOI:
10.1145/3457908
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Wu, Xintao
中科院分区:
文献类型:
--
作者:
Zheng, Panpan;Yuan, Shuhan;Wu, Xintao
Malicious insiders cause significant loss to organizations. Due to an extremely small number of malicious activities from insiders, insider threat is hard to detect. In this article, we present aDirichlet Marked Hawkes Process (DMHP)to detect malicious activities from insiders in real-time. DMHP combines the Dirichlet process and marked Hawkes processes to model the sequence of user activities. The Dirichlet process is capable of detecting unbounded user modes (patterns) of infinite user activities, while, for each detected user mode, one set of marked Hawkes processes is adopted to model user activities from time and activity type (e.g., WWW visit or send email) information so that different user modes are modeled by different sets of marked Hawkes processes. To achieve real-time malicious insider activity detection, the likelihood of the most recent activity calculated by DMHP is adopted as a score to measure the maliciousness of the activity. Since the majority of user activities are benign, those activities with low likelihoods are labeled as malicious activities. Experimental results on two datasets show the effectiveness of DMHP.
登录
查看更多内容
DOI:
10.1145/2897795.2897799
发表时间:
2016
期刊:
Proceedings of the 11th Annual Cyber and Information Security Research Conference
影响因子:
--
作者:
Ameya Sanzgiri;D. Dasgupta
通讯作者:
D. Dasgupta
DOI:
--
发表时间:
2017-01
期刊:
--
影响因子:
--
作者:
Hongteng Xu;H. Zha
通讯作者:
Hongteng Xu;H. Zha
DOI:
--
发表时间:
2018
期刊:
影响因子:
--
作者:
J. Rasmussen
通讯作者:
J. Rasmussen
影响因子:
4.4
作者:
Blei, David M.;Jordan, Michael I.
通讯作者:
Jordan, Michael I.
DOI:
10.1109/icdm.2012.127
发表时间:
2012
期刊:
2012 IEEE 12th International Conference on Data Mining
影响因子:
--
作者:
Hao Huang;Hong Qin;Shinjae Yoo;Dantong Yu
通讯作者:
Dantong Yu