节点文献
基于图神经网络的内部威胁行为检测模型
Model of Insider Threat Behavior Detection Based on Graph Neural Network
【摘要】 基于现有针对用户行为序列进行内部威胁行为检测的模型存在无法很好处理长序列的缺陷,设计了一种新的基于图神经网络的内部威胁行为检测模型,将用户行为序列转换为图结构,把对长序列的处理转换为对子图结构的处理.实验设计了描述用户行为的图结构,用于以图数据形式保存用户行为,并针对该图结构具有异构、边上存有数据的特点,优化了基线图神经网络模型.实验结果证明,提出的模型在区分正常和威胁行为的二分类任务中,ROC AUC值比基线模型提高7%,Macro-F1值提高7%,在区分具体威胁类型的六分类任务中,该模型的Macro-F1值比基线模型提高10%.
【Abstract】 This paper designs a new detection model based on graph neural networks to address the shortcomings of existing models for insider threat behavior detection based on user behavior sequences,which cannot handle long sequences well.The model converts user behavior sequences into a graph structure and transforms the processing of long sequences into the processing of subgraph structures.The experiment designs a graph structure to describe user behavior,which is used to store user behavior in the form of graph data.The baseline GNN model is optimized for this graph structure,which is heterogeneous and has data stored on its edges.The experimental results show that,for the binary classification task of distinguishing normal and threatening behavior,the ROC AUC value of the proposed model is improved by 7% and the Macro-F1 value is improved by 7% compared to the baseline model.In the six-class classification task of distinguishing specific threat types,the Macro-F1 value of the proposed model improves by 10% compared to the baseline model.
【Key words】 graph neural network; insider threat; heterogeneous graph; behavior detection; attention mechanism;
- 【文献出处】 信息安全研究 ,Journal of Information Security Research , 编辑部邮箱 ,2025年07期
- 【分类号】TP183;TP309
- 【下载频次】36