对用户和实体行为分析的集群算法的全面调查
Pierpaolo Artioli1, Antonio Maci1, Alessio Magrì1
1Cybersecurity Laboratory, BV TECH S.p.A., Milan, Italy.
Frontiers in big data
|May 24, 2024
概括
本研究评估了用于用户和实体行为分析 (UEBA) 的机器学习 (ML) 集群算法,以提高网络安全. HDBSCAN和DenMune在检测网络异常方面表现出强的表现.
科学领域:
- 网络安全 网络安全
- 机器学习 机器学习
- 网络安全 网络安全
背景情况:
- 政府机构要求加强网络安全系统,以积极发现和应对事件.
- 安全操作中心 (SOC) 将人类专业知识与机器学习 (ML) 整合起来,以实现有效的网络安全.
- 安全信息和事件管理 (SIEM) 平台,通常与用户和实体行为分析 (UEBA) 引擎,对于监控网络事件和用户/实体行为至关重要.
研究的目的:
- 对UEBA应用程序的传统和新兴集群算法的有效性进行全面分析.
- 弥合在UEBA中的ML研究和实际的网络安全实施之间的差距.
- 在各种用户实体交互场景中评估聚类算法.
主要方法:
- 研究了15个集群算法,包括传统和新兴技术.
- 利用现有文献中的三个数据集进行评估.
- 专注于无监督学习范式,因为异常行为的未知性质.
主要成果:
- 在CERT的行为相关数据集上,HDBSCAN和DenMune表现出有前途的表现.
- 这些算法有效地分组了用户实体行为,密度接近实际用户数量.
- 该研究提供了在各种UEBA环境中对聚类算法的彻底比较.
结论:
- 聚类算法,特别是HDBSCAN和DenMune,显示出增强UEBA能力的巨大潜力.
- 通过ML有效实施UEBA可以加强主动的网络安全措施.
- 进一步的研究和这些发现的实际应用可以加强组织安全.
相关概念视频
Behavior Modification
141
Behavioral approaches have often been criticized for ignoring mental processes and focusing solely on observable behavior. However, these approaches provide an optimistic perspective for individuals seeking to change their behaviors. Rather than concentrating on intrinsic personality traits, behavioral approaches suggest that even longstanding habits can be modified by changing the reward contingencies that maintain them.
A real-world application of operant conditioning principles is applied...
A real-world application of operant conditioning principles is applied...
141
Cluster Sampling Method
11.9K
Appropriate sampling methods ensure that samples are drawn without bias and accurately represent the population. Because measuring the entire population in a study is not practical, researchers use samples to represent the population of interest.
To choose a cluster sample, divide the population into clusters (groups) and then randomly select some of the clusters. All the members from these clusters are in the cluster sample. For example, if you randomly sample four departments from your...
To choose a cluster sample, divide the population into clusters (groups) and then randomly select some of the clusters. All the members from these clusters are in the cluster sample. For example, if you randomly sample four departments from your...
11.9K


