基于用户行为的内部威胁检测模型,使用LSTM集成的射频模型
S K Uma Maheswaran1, L Rajasekar2, Ziaul Haque Choudhury3
1Department of Mathematics, Sri Sai Ram Engineering College, Chennai, India.
概括
这项研究介绍了一种混合深度长期短期记忆随机森林 (LSTM-RF) 模型,用于内部威胁检测. 该模型有效地使用用户行为数据识别内部威胁,在检测各种攻击方面达到高精度.
科学领域:
- 网络安全 网络安全
- 数据科学数据科学数据科学
- 机器学习 机器学习
背景情况:
- 内部威胁对组织构成重大风险,其特点是数据不平衡和用户行为不断变化.
- 现有的检测方法难以应对内部威胁识别的复杂性.
研究的目的:
- 使用混合深度学习方法开发一个强大的内部威胁检测模型.
- 在威胁识别中应对数据不平衡和动态用户行为等挑战.
主要方法:
- 开发了一种混合深度长期短期记忆随机森林 (LSTM-RF) 模型,用于基于用户行为的威胁检测.
- 用户日志数据被预处理,规范化,并使用Spearman的等级相关系数进行特征选择.
- 在LSTM-RF分类器被训练在选定的功能,以识别内部威胁,如恶意软件,身份验证和网络鱼攻击.
主要成果:
- 混合LSTM-RF模型实现了96%的准确性,90%的精度,90%的特异性,97%的灵敏性和94%的F1得分.
- 该模型在模拟攻击过程中证明了系统内内部威胁的有效检测.
结论:
- 拟议的混合LSTM-RF模型为内部威胁检测提供了一个高度准确和有效的解决方案.
- 这种方法成功地减轻了与数据不平衡和网络安全中用户行为转变相关的挑战.
相关概念视频
Steps in Outbreak Investigation
97
In the ever-evolving field of public health, statistical analysis serves as a cornerstone for understanding and managing disease outbreaks. By leveraging various statistical tools, health professionals can predict potential outbreaks, analyze ongoing situations, and devise effective responses to mitigate impact. For that to happen, there are a few possible stages of the analysis:
97
Stereotype Content Model
13.9K
The Stereotype Content Model (SCM) was first proposed by Susan Fiske and her colleagues (Fiske, Cuddy, Glick & Xu, 2002; see also Fiske, 2012 and Fiske, 2017). The SCM specifies that when someone encounters a new group, they will stereotype them based on two metrics: warmth—or that group’s perceived intent, and how likely they are to provide help or inflict harm—and competence—or their ability to carry out that objective. Depending on the warmth-competence...
13.9K


