首页> 外文会议>IEEE Symposium on Visualization for Cyber Security >User Behavior Map: Visual Exploration for Cyber Security Session Data
【24h】

User Behavior Map: Visual Exploration for Cyber Security Session Data

机译:用户行为图:网络安全会话数据的可视化探索

获取原文

摘要

User behavior analysis is complex and especially crucial in the cyber security domain. Understanding dynamic and multi-variate user behavior are challenging. Traditional sequential and timeline based method cannot easily address the complexity of temporal and relational features of user behaviors. We propose a map-based visual metaphor and create an interactive map for encoding user behaviors. It enables analysts to explore and identify user behavior patterns and helps them to understand why some behaviors are regarded as anomalous. We experiment with a real dataset containing multiple user sessions, consisting of sequences of diverse types of actions. In the behavior map, we encode an action as a city and user sessions as trajectories going through the cities. The position of the cities is determined by the sequential and temporal relationship of actions. Spatial and temporal patterns on the map reflect behavior patterns in the action space. In the case study, we illustrate how we explore relationships between actions, identify patterns of the typical session and detect anomaly behaviors.
机译:用户行为分析非常复杂,在网络安全领域尤其重要。了解动态和多变的用户行为具有挑战性。传统的基于顺序和时间轴的方法无法轻松解决用户行为的时间和关系特征的复杂性。我们提出了一个基于地图的视觉隐喻,并创建了一个用于编码用户行为的交互式地图。它使分析人员能够探索和识别用户行为模式,并帮助他们理解为什么某些行为被视为异常。我们尝试使用包含多个用户会话的真实数据集,其中包含不同类型的操作序列。在行为图中,我们将动作编码为城市,并将用户会话编码为通过城市的轨迹。城市的位置取决于行动的顺序和时间关系。地图上的时空模式反映了动作空间中的行为模式。在案例研究中,我们说明了如何探索动作之间的关系,识别典型会话的模式并检测异常行为。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号