La Trobe

A graph empowered insider threat detection framework based on daily activities

Download (925.44 kB)
journal contribution
posted on 2023-11-14, 03:29 authored by W Hong, Jiao YinJiao Yin, M You, H Wang, Jinli CaoJinli Cao, J Li, M Liu, C Man
While threats from outsiders are easier to alleviate, effective ways seldom exist to handle threats from insiders. The key to managing insider threats lies in engineering behavioral features efficiently and classifying them correctly. To handle challenges in feature engineering, we propose an integrated feature engineering solution based on daily activities, combining manually-selected features and automatically-extracted features together. Particularly, an LSTM auto-encoder is introduced for automatic feature engineering from sequential activities. To improve detection, a residual hybrid network (ResHybnet) containing GNN and CNN components is also proposed along with an organizational graph, taking a user-day combination as a node. Experimental results show that the proposed LSTM auto-encoder could extract hidden patterns from sequential activities efficiently, improving F1 score by 0.56%. Additionally, with the designed residual link, our ResHybnet model works well to boost performance and has outperformed the best of other models by 1.97% on the same features. We published our code on GitHub: https://github.com/Wayne-on-the-road/ResHybnet.

Funding

This work was partially supported by the Research Program of Chongqing University of Arts and Sciences, China (Grant No. P2020RG08).

History

Publication Date

2023-10-01

Journal

ISA Transactions

Volume

141

Pagination

9p. (p. 84-92)

Publisher

Elsevier

ISSN

0019-0578

Rights Statement

© 2023 The Author(s). Published by Elsevier Ltd on behalf of ISA. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).

Usage metrics

    Journal Articles

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC