ITDBERT - Temporal-semantic Representation for Insider Threat Detection.

Weiqing Huang,He Zhu,Ce Li,Qiujian Lv,Yan Wang,Haitian Yang
DOI: https://doi.org/10.1109/iscc53001.2021.9631538
2021-01-01
Abstract:The objective and universal nature of user behavior data make it the primary data for insider threat detection. Existing solutions treat user behavior as atomic symbols and do not consider behavior semantic information. Meanwhile, fine-grained temporal information is ignored despite its relevance to describe user behavior. Such approaches inevitably lead to unsatisfactory performance and generalization. In this paper, we propose ITDBERT which embeds temporal information into behavior and catches the fused semantic representation via pre-trained language models. ITDBERT also leverages attention-based Bi-LSTM to provide behavior-level detection results. To verify the effectiveness of our proposed method, we conduct comparison experiments on Cert datasets. Our proposed model achieves an F1-score of 0.9243 in day-level insider threat detection, which outperforms baselines.
What problem does this paper attempt to address?