Detecting and Identifying Insider Threats Based on Advanced Clustering Methods

Autor: Oksana Nikiforova, Andrejs Romanovs, Vitaly Zabiniako, Jurijs Kornienko
Jazyk: angličtina
Rok vydání: 2024
Předmět:
Zdroj: IEEE Access, Vol 12, Pp 30242-30253 (2024)
Druh dokumentu: article
ISSN: 2169-3536
DOI: 10.1109/ACCESS.2024.3365424
Popis: This paper explores the analysis of user behavior in information systems through audit records, creating a behavior model represented as a graph. The model captures actions over a specified period, facilitating real-time comparison to identify insider threats exploring anomalies detected in behavior models. “e-StepControl,” developed by “ABC software” Ltd., incorporates this approach for monitoring user behavior in different business environments. The study proposes enhancing this solution with automatic user clustering, achieved by grouping individuals exhibiting similar behavior patterns using AI/ML algorithms. The research evaluates various clustering methods, discussing their suitability for grouping users based on their behavior. The subsequent step involves leveraging user class behavior models to identify anomalies by comparing an individual’s actions with the behavior model expected in their specific user group. This extension aims to enhance the system’s ability to detect potentially malicious activities, providing data security administrators with timely alerts in case of deviations from typical behavior.
Databáze: Directory of Open Access Journals