CPID: Insider Threat Detection using Profiling and Cyber-Persona Identification

Badis Racherache,Paria Shirani,Andrei Soeanu,Mourad Debbabi
DOI: https://doi.org/10.1016/j.cose.2023.103350
2023-06-22
Abstract:In digital environments, network administrators can benefit from the advanced network traffic monitoring capabilities with respect to the type of users (persona) and their specific network activities. This can be leveraged to derive corresponding persona profiles that can be subsequently used to detect anomalies and security events. Also, upon the occurrence and detection of a security event, it is important to get full details on the underlying entities and to gain relevant insights to mitigate and prevent such occurrences in the future. In this context, this paper proposes an innovative approach leveraging machine learning techniques along with deep learning for persona-specific traffic profile generation. This capability can be deployed as part of online traffic monitoring solutions for persona identification and anomalous network behaviour detection, where no software needs to be installed on deployed workstations. Performed experiments indicate that the proposed approach is efficient, scalable, and suitable for near real-time deployment scenarios.
computer science, information systems
What problem does this paper attempt to address?