English
Related papers

Related papers: Deep Learning for Unsupervised Insider Threat Dete…

200 papers

Insider threat detection presents unique challenges due to the authorized status of malicious actors and the subtlety of anomalous behaviors. Existing machine learning methods often treat user activity as isolated events, thereby failing to…

Machine Learning · Computer Science 2025-07-11 Mohamed Elbasheer , Adewale Akinfaderin

In modern world the importance of cybersecurity of various systems is increasing from year to year. The number of information security events generated by information security tools grows up with the development of the IT infrastructure. At…

Cryptography and Security · Computer Science 2025-06-17 Evgeniy Eremin

Insider threats are one of the most damaging risk factors for the IT systems and infrastructure of a company or an organization; identification of insider threats has prompted the interest of the world academic research community, with…

Cryptography and Security · Computer Science 2021-09-07 Vasileios Koutsouvelis , Stavros Shiaeles , Bogdan Ghita , Gueltoum Bendiab

Insider threats are the cyber attacks from within the trusted entities of an organization. Lack of real-world data and issue of data imbalance leave insider threat analysis an understudied research area. To mitigate the effect of skewed…

Cryptography and Security · Computer Science 2021-07-09 R G Gayathri , Atul Sajjanhar , Yong Xiang , Xingjun Ma

Enterprises and organizations are faced with potential threats from insider employees that may lead to serious consequences. Previous studies on insider threat detection (ITD) mainly focus on detecting abnormal users or abnormal time…

Cryptography and Security · Computer Science 2024-03-19 Xiangrui Cai , Yang Wang , Sihan Xu , Hao Li , Ying Zhang , Zheli Liu , Xiaojie Yuan

To be prepared against cyberattacks, most organizations resort to security information and event management systems to monitor their infrastructures. These systems depend on the timeliness and relevance of the latest updates, patches and…

Machine Learning · Computer Science 2019-04-03 Nuno Dionísio , Fernando Alves , Pedro M. Ferreira , Alysson Bessani

The increasing popularity of server usage has brought a plenty of anomaly log events, which have threatened a vast collection of machines. Recognizing and categorizing the anomalous events thereby is a much salient work for our systems,…

Distributed, Parallel, and Cluster Computing · Computer Science 2018-01-03 Jiechao Cheng , Rui Ren , Lei Wang , Jianfeng Zhan

We describe the motivation and design for esINSIDER, an automated tool that detects potential persistent and insider threats in a network. esINSIDER aggregates clues from log data, over extended time periods, and proposes a small number of…

Cryptography and Security · Computer Science 2019-04-09 M. Arthur Munson , Jason Kichen , Dustin Hillard , Ashley Fidler , Peiter Zatko

Deep learning solutions are instrumental in cybersecurity, harnessing their ability to analyze vast datasets, identify complex patterns, and detect anomalies. However, malevolent actors can exploit these capabilities to orchestrate…

Cryptography and Security · Computer Science 2024-12-19 Shalini Saini , Anitha Chennamaneni , Babatunde Sawyerr

APT, known as Advanced Persistent Threat, is a difficult challenge for cyber defence. These threats make many traditional defences ineffective as the vulnerabilities exploited by these threats are insiders who have access to and are within…

Cryptography and Security · Computer Science 2021-09-01 Mohammad Mamun , Kevin Shi

Cyber attacks constitute a significant threat to organizations with implications ranging from economic, reputational, and legal consequences. As cybercriminals' techniques get sophisticated, information security professionals face a more…

Cryptography and Security · Computer Science 2021-04-01 Emrah Tufan , Cihangir Tezcan , Cengiz Acartürk

Insiders usually cause significant losses to organizations and are hard to detect. Currently, various approaches have been proposed to achieve insider threat detection based on analyzing the audit data that record information of the…

Cryptography and Security · Computer Science 2019-10-11 Shuhan Yuan , Panpan Zheng , Xintao Wu , Qinghua Li

Previous works on the CERT insider threat detection case have neglected graph and text features despite their relevance to describe user behavior. Additionally, existing systems heavily rely on feature engineering and audit data aggregation…

Machine Learning · Computer Science 2020-07-15 Mathieu Garchery , Michael Granitzer

Anomaly detection in event logs is a promising approach for intrusion detection in enterprise networks. By building a statistical model of usual activity, it aims to detect multiple kinds of malicious behavior, including stealthy tactics,…

Cryptography and Security · Computer Science 2022-06-29 Corentin Larroche , Johan Mazel , Stephan Clémençon

Nowadays, the volume of network traffic continues to grow, along with the frequency and sophistication of attacks. This scenario highlights the need for solutions capable of continuously adapting, since network behavior is dynamic and…

In order to detect unknown intrusions and runtime errors of computer programs, the cyber-security community has developed various detection techniques. Anomaly detection is an approach that is designed to profile the normal runtime behavior…

Cryptography and Security · Computer Science 2021-06-03 Byunggu Yu , Junwhan Kim

Intrusion Detection Systems are widely used to detect cyberattacks, especially on protocols vulnerable to hacking attacks such as SOME/IP. In this paper, we present a deep learning-based sequential model for offline intrusion detection on…

Cryptography and Security · Computer Science 2021-10-12 Natasha Alkhatib , Hadi Ghauch , Jean-Luc Danger

Anomaly detection is the task of identifying abnormal behavior of a system. Anomaly detection in computational workflows is of special interest because of its wide implications in various domains such as cybersecurity, finance, and social…

Machine Learning · Computer Science 2023-10-03 Hongwei Jin , Krishnan Raghavan , George Papadimitriou , Cong Wang , Anirban Mandal , Ewa Deelman , Prasanna Balaprakash

Insiders are the trusted entities in the organization, but poses threat to the with access to sensitive information network and resources. The insider threat detection is a well studied problem in security analytics. Identifying the…

Cryptography and Security · Computer Science 2021-06-29 Gayathri R G , Atul Sajjanhar , Yong Xiang

Cyber incidents can have a wide range of cause from a simple connection loss to an insistent attack. Once a potential cyber security incidents and system failures have been identified, deciding how to proceed is often complex. Especially,…

Computers and Society · Computer Science 2020-07-16 Sandro Passarelli , Cem Gündogan , Lars Stiemert , Matthias Schopp , Peter Hillmann