Visible to the public Insider Threat Detection using an Artificial Immune system Algorithm

TitleInsider Threat Detection using an Artificial Immune system Algorithm
Publication TypeConference Paper
Year of Publication2018
AuthorsIgbe, O., Saadawi, T.
Conference Name2018 9th IEEE Annual Ubiquitous Computing, Electronics Mobile Communication Conference (UEMCON)
Date Publishednov
Keywordsanomaly detection, anomaly detection system, artificial immune system algorithm, artificial immune systems, CERT, computer emergency response team synthetic insider threat dataset, Ensemble, Human Behavior, insider threat, insider threat activities, Insider Threat Detection, learning (artificial intelligence), legitimate users, malicious insider, malicious insiders, Metrics, negative selection algorithm, negative selection algorithms, NSA, pattern classification, policy-based governance, pubcrawl, resilience, Resiliency, security of data
AbstractInsider threats result from legitimate users abusing their privileges, causing tremendous damage or losses. Malicious insiders can be the main threats to an organization. This paper presents an anomaly detection system for detecting insider threat activities in an organization using an ensemble that consists of negative selection algorithms (NSA). The proposed system classifies a selected user activity into either of two classes: "normal" or "malicious." The effectiveness of our proposed detection system is evaluated using case studies from the computer emergency response team (CERT) synthetic insider threat dataset. Our results show that the proposed method is very effective in detecting insider threats.
DOI10.1109/UEMCON.2018.8796583
Citation Keyigbe_insider_2018