TS-AUBD: A Novel Two-Stage Method for Abnormal User Behavior Detection

Yu Cao,Yilu Chen,Ye Wang,Ning Hu,Zhaoquan Gu,Yan Jia
DOI: https://doi.org/10.1007/978-981-97-7244-5_2
2024-01-01
Abstract:Malicious insider attacks are among the most destructive threats to enterprises. Solving the insider threat problem involves several challenges, including data imbalance and detection of anomalous behavior. This paper presents TS-AUBD, a two-stage method for abnormal user behavior detection. TS-AUBD consists of coarse-grained and fine-grained user-level models. TS-AUBD can not only effectively detect abnormal behaviors and users but also analyze the situation of abnormal behaviors presented in each abnormal user. Experiments were conducted on a publicly available standard dataset CERT R4.2. Results show that TS-AUBD shows better performance compared with the baseline model, with an accuracy of up to 99.9% for behavior detection and 99. 8% for user detection.
What problem does this paper attempt to address?