Insider Threat Detection Based on Deep Belief Network Feature Representation
Title | Insider Threat Detection Based on Deep Belief Network Feature Representation |
Publication Type | Conference Paper |
Year of Publication | 2017 |
Authors | Lin, L., Zhong, S., Jia, C., Chen, K. |
Conference Name | 2017 International Conference on Green Informatics (ICGI) |
ISBN Number | 978-1-5386-2280-3 |
Keywords | Collaboration, Data models, deep belief network, Electronic mail, feature extraction, feature representation, Human Behavior, human factors, Information systems, Insider Threat Detection, insider threats, Learning systems, Metrics, one-class SVM, policy-based governance, Postal services, pubcrawl, Resiliency, Training |
Abstract | Insider threat is a significant security risk for information system, and detection of insider threat is a major concern for information system organizers. Recently existing work mainly focused on the single pattern analysis of user single-domain behavior, which were not suitable for user behavior pattern analysis in multi-domain scenarios. However, the fusion of multi-domain irrelevant features may hide the existence of anomalies. Previous feature learning methods have relatively a large proportion of information loss in feature extraction. Therefore, this paper proposes a hybrid model based on the deep belief network (DBN) to detect insider threat. First, an unsupervised DBN is used to extract hidden features from the multi-domain feature extracted by the audit logs. Secondly, a One-Class SVM (OCSVM) is trained from the features learned by the DBN. The experimental results on the CERT dataset demonstrate that the DBN can be used to identify the insider threat events and it provides a new idea to feature processing for the insider threat detection. |
URL | https://ieeexplore.ieee.org/document/8117081 |
DOI | 10.1109/ICGI.2017.37 |
Citation Key | lin_insider_2017 |
- Insider Threat Detection
- Training
- Resiliency
- pubcrawl
- Postal services
- policy-based governance
- one-class SVM
- Metrics
- Learning systems
- Insider Threats
- collaboration
- Information systems
- Human Factors
- Human behavior
- feature representation
- feature extraction
- Electronic mail
- Deep Belief Network
- Data models