Insider Threat Detection Using Characterizing User Behavior.

Xuebin Wang,Qingfeng Tan,Jinqiao Shi,Shen Su,Meiqi Wang
DOI: https://doi.org/10.1109/dsc.2018.00077
2018-01-01
Abstract:With the rapid development of information technology, office automation is continuously improving. The data leakage problem resulting from insider threats is getting worse, legitimate users may abuse privileges or masquerade as other users, which may result in the loss of data. In this paper, a new data-centric approach is proposed to detect insider threat, which based on characterizing user behavior by extracting the features of user interaction behavior including keystroke dynamics and consecutive queries to model users' access patterns. Statistical learning algorithms are trained and tested from opening dataset to predict abnormal behavior patterns; experimental results indicate that the approach is very effective and accurate.
What problem does this paper attempt to address?