首页> 外文会议>49th Annual IEEE International Carnahan Conference on Security Technology >AD2: Anomaly detection on active directory log data for insider threat monitoring
【24h】

AD2: Anomaly detection on active directory log data for insider threat monitoring

机译:AD2:对活动目录日志数据进行异常检测以进行内部威胁监控

获取原文
获取原文并翻译 | 示例

摘要

What you see is not definitely believable is not a rare case in the cyber security monitoring. However, due to various tricks of camouflages, such as packing or virutal private network (VPN), detecting "advanced persistent threat"(APT) by only signature based malware detection system becomes more and more intractable. On the other hand, by carefully modeling users' subsequent behaviors of daily routines, probability for one account to generate certain operations can be estimated and used in anomaly detection. To the best of our knowledge so far, a novel behavioral analytic framework, which is dedicated to analyze Active Directory domain service logs and to monitor potential inside threat, is now first proposed in this project. Experiments on real dataset not only show that the proposed idea indeed explores a new feasible direction for cyber security monitoring, but also gives a guideline on how to deploy this framework to various environments.
机译:在网络安全监控中,您所看到的并非绝对令人信服。但是,由于各种伪装技巧,例如打包或虚拟专用网(VPN),仅基于签名的恶意软件检测系统检测“高级持久威胁”(APT)变得越来越棘手。另一方面,通过仔细地模拟用户的日常日常行为,可以估算一个帐户产生某些操作的可能性并将其用于异常检测。到目前为止,就我们所知,目前已经在该项目中首次提出了一种新颖的行为分析框架,该框架致力于分析Active Directory域服务日志并监视潜在的内部威胁。在真实数据集上进行的实验不仅表明所提出的想法确实为网络安全监视探索了一个新的可行方向,而且为如何将该框架部署到各种环境提供了指导。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号