课题基金 / 基金详情

SaTC: CORE: Small: Deep Learning for Insider Threat Detection

SaTC: CORE: Small: Deep Learning for Insider Threat Detection
SaTC:核心:小型:用于内部威胁检测的深度学习
批准号:
2103829
负责人:
Shuhan Yuan
金额:
$49.86万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-06-01 至 2025-05-31

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Insiders are malicious people within organizations who abuse their authorized access in a manner that compromises the confidentiality, integrity, or availability of information systems. Attacks from insiders are hard to detect and can cause significant loss to organizations. While the problem of insider threat detection has been studied for a long time, the traditional machine learning-based detection approaches, which heavily rely on feature engineering, are hard to accurately capture the behavior difference between insiders and normal users due to the dynamic and adaptive nature of insider threats. Advanced deep learning techniques provide a new paradigm to learn end-to-end insider threat detection models from complex user behavior data. This project develops a deep learning framework for insider threat detection. The project’s novelties are the development of self-supervised user behavior representation learning, few-shot learning for malicious session detection, reinforcement learning for adaptive behavior detection, and counterfactual explanations based malicious activity detection. The project’s broader significance and importance are to provide a novel toolset for detecting and mitigating internal security risks, which can be benefit industries and governments who are frequently under attacks from malicious insiders. This project develops novel deep learning approaches to detect malicious sessions through a) developing a self-supervised representation learning approach to encode user sessions into a low-dimensional embedding space without using any manually labeled data, b) advancing a few-shot learning framework via disentangled representation learning to detect malicious sessions with subtle activity changes, c) adapting reinforcement learning framework to identify dynamically evolving insider attacks, and d) proposing a counterfactual explanation approach to detect malicious activities in malicious sessions. The framework has the potential to extend to different types of fraud detection.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(16)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/icdm54844.2022.00115
发表时间: 2022-11
期刊: 2022 IEEE International Conference on Data Mining (ICDM)
影响因子: --
作者: [Xiao Han;Depeng Xu;Shuhan Yuan;Xintao Wu]
通讯作者: Xiao Han;Depeng Xu;Shuhan Yuan;Xintao Wu
Using Dirichlet Marked Hawkes Processes for Insider Threat Detection
使用狄利克雷标记霍克斯过程进行内部威胁检测
DOI: 10.1145/3457908
发表时间: 2022
期刊: Digital Threats: Research and Practice
影响因子: --
作者: [Zheng, Panpan, Yuan, Shuhan, Wu, Xintao]
通讯作者: Wu, Xintao
DOI: 10.48550/arxiv.2303.02318
发表时间: 2023-03
期刊: Chinese Journal of Geophysics
影响因子: --
作者: [Xiao Han;Lu Zhang;Yongkai Wu;Shuhan Yuan]
通讯作者: Xiao Han;Lu Zhang;Yongkai Wu;Shuhan Yuan
DOI: 10.48550/arxiv.2211.06571
发表时间: 2022-11
期刊:
影响因子: --
作者: [Xingyi Zhao;Lu Zhang;Depeng Xu;Shuhan Yuan]
通讯作者: Xingyi Zhao;Lu Zhang;Depeng Xu;Shuhan Yuan
14
    国内基金
    海外基金
    胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
    • 批准号:
      82371765
    • 项目类别:
      面上项目
    • 资助金额:
      50万元
    • 批准年份:
      2023
    • 负责人:
      谭广云
    • 依托单位:
    锕系元素5f-in-core的GTH赝势和基组的开发
    • 批准号:
      22303037
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2023
    • 负责人:
      鲁俊波
    • 依托单位:
    基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
    • 批准号:
      --
    • 项目类别:
      --
    • 资助金额:
      52万元
    • 批准年份:
      2022
    • 负责人:
      孙丙军
    • 依托单位:
    鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
    • 批准号:
      --
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2022
    • 负责人:
      叶成林
    • 依托单位: