1. Analyzing Data Granularity Levels for Insider Threat Detection Using Machine Learning
- Author
-
Nur Zincir-Heywood, Malcolm I. Heywood, and Duc C. Le
- Subjects
Ground truth ,Government ,Computer Networks and Communications ,business.industry ,Computer science ,Insider threat ,020206 networking & telecommunications ,02 engineering and technology ,Machine learning ,computer.software_genre ,Insider ,Action (philosophy) ,0202 electrical engineering, electronic engineering, information engineering ,Data analysis ,Artificial intelligence ,False positive rate ,Electrical and Electronic Engineering ,Set (psychology) ,business ,computer - Abstract
Malicious insider attacks represent one of the most damaging threats to networked systems of companies and government agencies. There is a unique set of challenges that come with insider threat detection in terms of hugely unbalanced data, limited ground truth, as well as behaviour drifts and shifts. This work proposes and evaluates a machine learning based system for user-centered insider threat detection. Using machine learning, analysis of data is performed on multiple levels of granularity under realistic conditions for identifying not only malicious behaviours, but also malicious insiders. Detailed analysis of popular insider threat scenarios with different performance measures are presented to facilitate the realistic estimation of system performance. Evaluation results show that the machine learning based detection system can learn from limited ground truth and detect new malicious insiders in unseen data with a high accuracy. Specifically, up to 85% of malicious insiders are detected at only 0.78% false positive rate. The system is also able to quickly detect the malicious behaviours, as low as 14 minutes after the first malicious action. Comprehensive result reporting allows the system to provide valuable insights to analysts in investigating insider threat cases.
- Published
- 2020
- Full Text
- View/download PDF