Differentiating User Authentication Graphs

Differentiating User Authentication Graphs
复制标题

区分用户认证图

DOI:
10.22667/jowua.2014.06.31.024
复制
发表时间:
2013
期刊:
2013 IEEE Security and Privacy Workshops
影响因子:
--
通讯作者:
James Wernicke
James Wernicke
中科院分区:
--
文献类型:
--
作者:
A. Kent;L. Liebrock;James Wernicke

文献摘要

被引文献

相似文献

使用集中式方法的身份验证是大多数大型企业计算机网络中的主要信任机制。本文提出用图形来表示网络中的用户认证活动。在真实的企业网络数据集上使用这种机制,我们发现非特权用户和具有系统管理权限的用户在大小和复杂性方面具有可区分的图属性。此外,我们发现用户身份验证图提供了对网络用户行为的直观洞察。我们相信,更详细地了解这些差异将有助于改进用户行为分析和难以捉摸的身份验证凭证滥用检测。
Authentication using centralized methods is a primary trust mechanism within most large-scale, enterprise computer networks. This paper proposes using graphs to represent user authentication activity within the network. Using this mechanism over a real enterprise network dataset, we find that non-privileged users and users with system administration privileges have distinguishable graph attributes in terms of size and complexity. In addition, we find that user authentication graphs provide intuitive insights into network user behavior. We believe that understanding these differences in even greater detail will lead to improved user behavior profiling and the elusive detection of authentication credential misuse.