arrow
返回

Applying One-Class Algorithms for Data Stream-Based Insider Threat Detection

delete2023-01-01
delete6
delete
OA
AI
R
Rafael Bruno Peccatiello *
J
João José Costa Gondim
L
Luís P. F. Garcia
DOI:10.1109/ACCESS.2023.3293825delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
An insider threat is anyone who has legitimate access to a particular organization's network and uses that access to harm that organization. Insider threats may act with or without intent, but when they have an intention, they usually also have some specific motivation. This motivation can vary, including but not limited to personal discontent, financial issues, and coercion. It is hard to face insider threats with traditional security solutions because those solutions are limited to the signature detection paradigm. To overcome this restriction, researchers have proposed using Machine Learning which can address Insider Threat issues more comprehensively. Some of them have used batch learning, and others have used stream learning. Batch approaches are simpler to implement, but the problem is how to apply them in the real world. That is because real insider threat scenarios have complex characteristics to address by batch learning. Although more complex, stream approaches are more comprehensive and feasible to implement. Some studies have also used unsupervised and supervised Machine Learning techniques, but obtaining labeled samples makes it hard to implement fully supervised solutions. This study proposes a framework that combines different data science techniques to address insider threat detection. Among them are using semi-supervised and supervised machine learning, data stream analysis, and periodic retraining procedures. The algorithms used in the implementation were Isolation Forest, Elliptic Envelop, and Local Outlier Factor. This study evaluated the results according to the values obtained by the precision, recall, and F1-Score metrics. The best results were obtained by the ISOF algorithm, with 0.78 for the positive class (malign) recall and 0.80 for the negative class (benign) recall.
Keyword:
Insider threat detection
data stream
machine learning
one-class classification

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

U
universidade de brasilia
学者数:
1.1W
论文数: 7.3K
被引数: 5
引用论文

引用论文

A Survey on Ensemble Learning for Data Stream Classification面向数据流分类的集成学习研究综述
err2017-03-27
err378
PREAI
errGomes, Heitor Murilo; Barddal, Jean Paul; Enembreck, Fabricio; Bifet, Albert
err分享
err收藏
Tailored conditions for controlled and fast growth of surface-grafted PNIPAM brushes
err2016-08-01
err0
PREAI
errA. Pomorska; K. Wolski; A. Puciul-Malinowska; S. Zapotoczny
err分享
err收藏
err分享
err收藏
Kinetics and mechanism of silver(III) reduction
err2002-05-01
err0
PREAI
errEdward T. Borish; Louis J. Kirschenbaum
err分享
err收藏
Kappa coefficients in medical research
err2002-06-19
err0
PREAI
errHelena Chmura Kraemer; Vyjeyanthi S. Periyakoil; Art Noda
err分享
err收藏
学者 查看更多内容