首页> 外文会议>IEEE International Conference on Intelligence and Security Informatics >Layered behavioral trace modeling for threat detection
【24h】

Layered behavioral trace modeling for threat detection

机译:用于威胁检测的分层行为跟踪建模

获取原文

摘要

A fundamental problem in detecting threats to security by monitoring computer usage is the high number of false positives that are created when analyzing a large data set for anomalous behavior. We address the problem by modeling user behavior at multiple scales so as to allow for the identification potential insider threats from users' logged activity by tracking users' activity over time. In this work, we apply a novel method for representing user activity at multiple temporal scales to a dataset that contains malicious behavior. We report our detection results and discuss how a layered detection method may be advantageous for the discovery of specific types of malicious behavior.
机译:通过监视计算机使用情况来检测对安全的威胁的一个基本问题是,在分析大型数据集的异常行为时会产生大量的误报。我们通过在多个尺度上对用户行为进行建模来解决该问题,以便通过跟踪用户随时间的活动来识别用户记录的活动中潜在的内部威胁。在这项工作中,我们将一种用于在多个时间尺度上表示用户活动的新颖方法应用于包含恶意行为的数据集。我们将报告检测结果,并讨论分层检测方法对于发现特定类型的恶意行为的优势。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号