首页> 外文OA文献 >Insider threat simulation and performance analysis of insider detection algorithms with role based models
【2h】

Insider threat simulation and performance analysis of insider detection algorithms with role based models

机译:基于角色模型的内部人员检测算法内部威胁仿真与性能分析

摘要

Insider threat problems are widespread in industry today. They have resulted in hugelosses to organizations. The security reports by leading organizations point out the fact that therehave been many more insider attacks in recent years than any other form of attack. Detection ofthese insider threats is a top priority. One problem facing the detection mechanisms is that thereal data for modeling is not easily available. This thesis describes a simulator which cansimulate the insiders and generate access information in the form of logs.Currently there are many methods which use data mining algorithms to detect insiderattacks. Role based detection is a well known mechanism to accurately distinguish insiderbehavior from the normal behavior. The thesis focuses on the advantages of using role basedmechanisms for insider threat detection. Five algorithms have been chosen and performanceanalysis of these under various scenarios is carried out. The thesis discusses these results indetail.The simulator is built on the Scalable Simulation Framework (SSF). It is an extension ofthe Boeing simulator, JANUS. The simulator uses behavior files to model an insider/normal userand generates the access information using Markov chains.
机译:内幕威胁问题在当今行业中十分普遍。它们给组织造成了巨大损失。领先组织的安全报告指出,近年来,内部攻击比任何其他形式的攻击都要多。检测这些内部威胁是头等大事。检测机制面临的一个问题是,难以轻易获得用于建模的真实数据。本文介绍了一种可以模拟内部人员并以日志形式生成访问信息的模拟器。当前,有很多使用数据挖掘算法来检测内部人员攻击的方法。基于角色的检测是一种众所周知的机制,可以准确地将内部行为与正常行为区分开。本文着重介绍了使用基于角色的机制进行内部威胁检测的优势。选择了五种算法,并在各种情况下对这些算法进行了性能分析。本文详细讨论了这些结果。模拟器基于可扩展模拟框架(SSF)构建。它是波音模拟器JANUS的扩展。该模拟器使用行为文件为内部人员/普通用户建模,并使用马尔可夫链生成访问信息。

著录项

  • 作者

    Nellikar Suraj;

  • 作者单位
  • 年度 2010
  • 总页数
  • 原文格式 PDF
  • 正文语种 {"code":"en","name":"English","id":9}
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号