节点文献
无监督异常值分数增强有监督内部威胁检测
Unsupervised Outlier Scores Enhance Supervised Insider Threat Detection
【摘要】 近年来,内部威胁检测和缓解的研究受到了组织和网络安全公司的日益关注。与传统的入侵检测任务不同,内部威胁中的恶意行为通常由授权人员执行,无法通过传统的行为审计手段来检测这类行为。提出了一种利用无监督异常值分数来增强有监督内部威胁检测的方法,通过集成有监督学习和无监督学习方法的优势,使用多种无监督异常值挖掘算法从底层数据中提取有用的表示,从而增强了有监督分类器在增强的特征空间上的预测能力。以上新颖的方法提供了卓越的性能,与其它优秀的异常检测方法相比,上述方法提供了更好的预测能力。在仅使用20%的计算预算下,上述方法达到86.12%的精确率,相比其它异常检测方法,在同等计算预算下,精确率提高最大12.5%。
【Abstract】 In recent years, research on insider threat detection and mitigation has received increasing attention from organizations and cybersecurity companies. Unlike traditional intrusion detection tasks, malicious behaviors in insider threats are usually performed by authorized personnel and cannot be detected through traditional behavioral auditing methods. This paper proposes a method to leverage unsupervised outlier scores to enhance supervised insider threat detection by integrating the advantages of supervised and unsupervised learning methods and using multiple unsupervised outlier mining algorithms to extract from the underlying data. Useful representations, thereby enhancing the predictive power of supervised classifiers on the enhanced feature space. This novel approach provides superior performance, and our method provides better predictive power compared to other excellent anomaly detection methods. Using only 20% of the computing budget, our method achieved an accuracy of 86.12%. Compared with other anomaly detection methods, the accuracy increased by up to 12.5% under the same computing budget.
【Key words】 Representation learning; Unsupervised ensemble; Outlier scoring; Principal component analysis; Extreme gradient boosting;
- 【文献出处】 计算机仿真 ,Computer Simulation , 编辑部邮箱 ,2025年07期
- 【分类号】TP393.08;TP18
- 【下载频次】13