课题基金 / 基金详情

SaTC: CORE: Small: Deep Learning for Insider Threat Detection

SaTC: CORE: Small: Deep Learning for Insider Threat Detection
SaTC:核心:小型:用于内部威胁检测的深度学习
批准号:
2103829
负责人:
Shuhan Yuan
金额:
$49.86万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-06-01 至 2025-05-31

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
内部人员是组织内的恶意人员,他们滥用授权访问权限,从而危及信息系统的机密性、完整性或可用性。来自内部人员的攻击很难被发现,可能会给组织造成重大损失。内部威胁检测问题已经研究了很长时间,但由于内部威胁的动态性和自适应性,传统的基于机器学习的检测方法严重依赖于特征工程,难以准确捕捉内部用户和普通用户之间的行为差异。先进的深度学习技术提供了一种新的范式,可以从复杂的用户行为数据中学习端到端的内部威胁检测模型。该项目开发了一个用于内部威胁检测的深度学习框架。该项目的创新之处在于开发了自监督用户行为表示学习、用于恶意会话检测的少量学习、用于自适应行为检测的强化学习以及基于反事实解释的恶意活动检测。该项目更广泛的意义和重要性在于提供一种用于检测和减轻内部安全风险的新工具集,这可以使经常受到恶意内部人员攻击的行业和政府受益。该项目开发了新的深度学习方法来检测恶意会话,方法是:a)开发一种自监督表示学习方法,将用户会话编码到低维嵌入空间中,而不使用任何手动标记的数据,B)通过分解表示学习来推进一个少量学习框架,以检测具有细微活动变化的恶意会话,c)采用强化学习框架来识别动态演变的内部攻击,以及d)提出反事实解释方法来检测恶意会话中的恶意活动。该框架有可能扩展到不同类型的欺诈检测。该奖项反映了NSF的法定使命,并被认为值得通过使用基金会的知识价值和更广泛的影响审查标准进行评估。
英文摘要
Insiders are malicious people within organizations who abuse their authorized access in a manner that compromises the confidentiality, integrity, or availability of information systems. Attacks from insiders are hard to detect and can cause significant loss to organizations. While the problem of insider threat detection has been studied for a long time, the traditional machine learning-based detection approaches, which heavily rely on feature engineering, are hard to accurately capture the behavior difference between insiders and normal users due to the dynamic and adaptive nature of insider threats. Advanced deep learning techniques provide a new paradigm to learn end-to-end insider threat detection models from complex user behavior data. This project develops a deep learning framework for insider threat detection. The project’s novelties are the development of self-supervised user behavior representation learning, few-shot learning for malicious session detection, reinforcement learning for adaptive behavior detection, and counterfactual explanations based malicious activity detection. The project’s broader significance and importance are to provide a novel toolset for detecting and mitigating internal security risks, which can be benefit industries and governments who are frequently under attacks from malicious insiders. This project develops novel deep learning approaches to detect malicious sessions through a) developing a self-supervised representation learning approach to encode user sessions into a low-dimensional embedding space without using any manually labeled data, b) advancing a few-shot learning framework via disentangled representation learning to detect malicious sessions with subtle activity changes, c) adapting reinforcement learning framework to identify dynamically evolving insider attacks, and d) proposing a counterfactual explanation approach to detect malicious activities in malicious sessions. The framework has the potential to extend to different types of fraud detection.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(16)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/icdm54844.2022.00115
发表时间: 2022-11
期刊: 2022 IEEE International Conference on Data Mining (ICDM)
影响因子: --
作者: [Xiao Han;Depeng Xu;Shuhan Yuan;Xintao Wu]
通讯作者: Xiao Han;Depeng Xu;Shuhan Yuan;Xintao Wu
Using Dirichlet Marked Hawkes Processes for Insider Threat Detection
使用狄利克雷标记霍克斯过程进行内部威胁检测
DOI: 10.1145/3457908
发表时间: 2022
期刊: Digital Threats: Research and Practice
影响因子: --
作者: [Zheng, Panpan, Yuan, Shuhan, Wu, Xintao]
通讯作者: Wu, Xintao
DOI: 10.48550/arxiv.2303.02318
发表时间: 2023-03
期刊: Chinese Journal of Geophysics
影响因子: --
作者: [Xiao Han;Lu Zhang;Yongkai Wu;Shuhan Yuan]
通讯作者: Xiao Han;Lu Zhang;Yongkai Wu;Shuhan Yuan
DOI: 10.48550/arxiv.2211.06571
发表时间: 2022-11
期刊:
影响因子: --
作者: [Xingyi Zhao;Lu Zhang;Depeng Xu;Shuhan Yuan]
通讯作者: Xingyi Zhao;Lu Zhang;Depeng Xu;Shuhan Yuan
共 14 条
    国内基金
    海外基金
    胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
    • 批准号:
      82371765
    • 项目类别:
      面上项目
    • 资助金额:
      50万元
    • 批准年份:
      2023
    • 负责人:
      谭广云
    • 依托单位:
    锕系元素5f-in-core的GTH赝势和基组的开发
    • 批准号:
      22303037
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2023
    • 负责人:
      鲁俊波
    • 依托单位:
    基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
    • 批准号:
      --
    • 项目类别:
      --
    • 资助金额:
      52万元
    • 批准年份:
      2022
    • 负责人:
      孙丙军
    • 依托单位:
    鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
    • 批准号:
      --
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2022
    • 负责人:
      叶成林
    • 依托单位: