Double-layer Detection of Internal Threat in Enterprise Systems Based on Deep Learning

Daojing He,Xin Lv,Xueqian Xu,Sammy Chan,Kim-Kwang Raymond Choo
DOI: https://doi.org/10.1109/tifs.2024.3372771
IF: 7.231
2024-01-01
IEEE Transactions on Information Forensics and Security
Abstract:In recent years, phishing mail-mediated attacks are proliferating. When victims are enterprise employees, internal security of the enterprise systems will also be threatened. Facing the advanced phishing email attacks and complex insider threat attacks, enterprise systems equipped with traditional machine learning models cannot detect such attacks effectively. Therefore, we propose a double-layer detection framework in this paper. Firstly, from the perspective of individual security, Long Short-Term Memory (LSTM) and extreme gradient boosting tree (XGBoost) are used to build a phishing email detection model. The model generalization ability and precision rate are improved by adding a custom loss function in the training process. Then, from the perspective of group security, Bidirectional LSTM and Attention mechanism are used to build an insider threat detection model. Our model has better results for multi-domain time series and anomaly detection in comparison to different models and existing insider threat detection models. We test the effectiveness of the proposed framework through real phishing email cases and insider threat attack events on our simulation verification platform. The experimental results demonstrate that our proposed framework can protect enterprise systems from phishing attacks and insider threats.
computer science, theory & methods,engineering, electrical & electronic
What problem does this paper attempt to address?