Visible to the public Insider Threat Detection Based on Deep Belief Network Feature Representation

TitleInsider Threat Detection Based on Deep Belief Network Feature Representation
Publication TypeConference Paper
Year of Publication2017
AuthorsLin, L., Zhong, S., Jia, C., Chen, K.
Conference Name2017 International Conference on Green Informatics (ICGI)
ISBN Number978-1-5386-2280-3
KeywordsCollaboration, Data models, deep belief network, Electronic mail, feature extraction, feature representation, Human Behavior, human factors, Information systems, Insider Threat Detection, insider threats, Learning systems, Metrics, one-class SVM, policy-based governance, Postal services, pubcrawl, Resiliency, Training
Abstract

Insider threat is a significant security risk for information system, and detection of insider threat is a major concern for information system organizers. Recently existing work mainly focused on the single pattern analysis of user single-domain behavior, which were not suitable for user behavior pattern analysis in multi-domain scenarios. However, the fusion of multi-domain irrelevant features may hide the existence of anomalies. Previous feature learning methods have relatively a large proportion of information loss in feature extraction. Therefore, this paper proposes a hybrid model based on the deep belief network (DBN) to detect insider threat. First, an unsupervised DBN is used to extract hidden features from the multi-domain feature extracted by the audit logs. Secondly, a One-Class SVM (OCSVM) is trained from the features learned by the DBN. The experimental results on the CERT dataset demonstrate that the DBN can be used to identify the insider threat events and it provides a new idea to feature processing for the insider threat detection.

URLhttps://ieeexplore.ieee.org/document/8117081
DOI10.1109/ICGI.2017.37
Citation Keylin_insider_2017