一个图表授权内部威胁检测框架,基于日常活动
Wei Hong1, Jiao Yin2, Mingshan You2
1School of Artificial Intelligence, Chongqing University of Arts and Sciences, Chongqing, 402160, China.
ISA transactions
|July 14, 2023
概括
这项研究引入了通过手动和自动功能工程的结合来检测内部威胁的新方法. 一个长短期内存 (LSTM) 自动编码器和一个剩余混合网络 (ResHybnet) 显著提高了检测准确性.
科学领域:
- 计算机科学 计算机科学
- 网络安全 网络安全
- 机器学习 机器学习
背景情况:
- 内部威胁对组织安全构成重大挑战.
- 现有的检测内部威胁的方法经常与有效的特征工程和分类扎.
- 内幕行为的复杂性需要先进的分析方法.
研究的目的:
- 开发一个集成的功能工程解决方案,以改进内部威胁检测.
- 提出一种新的深度学习架构,用于分析连续的用户活动.
- 提高内部威胁检测系统的准确性和性能.
主要方法:
- 一个集成的特征工程方法,结合了手动选择和自动提取的特征.
- 使用长短期内存 (LSTM) 自动编码器,自动从连续活动中提取特征.
- 开发了一个剩余混合网络 (ResHybnet),结合了图形神经网络 (GNN) 和卷积神经网络 (CNN) 与组织图.
主要成果:
- LSTM自动编码器有效地从连续活动中提取隐藏的模式,F1得分提高了0.56%.
- 拟议的ResHybnet模型,具有剩余链接,在相同的特征上以1.97%优于现有模型.
- 综合方法在分类和检测内部威胁方面表现出卓越的表现.
结论:
- 拟议的LSTM自动编码器和ResHybnet模型在内部威胁检测方面取得了重大进展.
- 将自动功能提取与先进的网络架构相结合,可以增强检测能力.
- 开发的方法为管理复杂的内部威胁提供了有效的解决方案.
相关概念视频
Steps in Outbreak Investigation
153
In the ever-evolving field of public health, statistical analysis serves as a cornerstone for understanding and managing disease outbreaks. By leveraging various statistical tools, health professionals can predict potential outbreaks, analyze ongoing situations, and devise effective responses to mitigate impact. For that to happen, there are a few possible stages of the analysis:
153
Guidelines and Strategies for Safe Computer Charting
833
The guidelines and strategies provided by the American Nurses Association (ANA) and the Canadian Nurses Association (CNA) offer essential principles for ensuring safe and secure computer charting systems in healthcare settings. Let's break down each recommendation:
Maintain Confidentiality and Security:
Maintain Confidentiality and Security:
833


