Skip to main navigation Skip to search Skip to main content

Detecting Insider Threat from Behavioral Logs Based on Ensemble and Self-Supervised Learning

  • Chunrui Zhang
  • , Shen Wang*
  • , Dechen Zhan
  • , Tingyue Yu
  • , Tiangang Wang
  • , Mingyong Yin
  • *Corresponding author for this work
  • Faculty of Computing, Harbin Institute of Technology
  • China Academy of Engineering Physics

Research output: Contribution to journalArticlepeer-review

Abstract

Recent studies have highlighted that insider threats are more destructive than external network threats. Despite many research studies on this, the spatial heterogeneity and sample imbalance of input features still limit the effectiveness of existing machine learning-based detection methods. To solve this problem, we proposed a supervised insider threat detection method based on ensemble learning and self-supervised learning. Moreover, we propose an entity representation method based on TF-IDF to improve the detection effect. Experimental results show that the proposed method can effectively detect malicious sessions in CERT4.2 and CERT6.2 datasets, where the AUCs are 99.2% and 95.3% in the best case.

Original languageEnglish
Article number4148441
JournalSecurity and Communication Networks
Volume2021
DOIs
StatePublished - 2021
Externally publishedYes

Fingerprint

Dive into the research topics of 'Detecting Insider Threat from Behavioral Logs Based on Ensemble and Self-Supervised Learning'. Together they form a unique fingerprint.

Cite this