User Attributes Profiling Method and Application in Insider Threat Detection

ZHONG Ya1,GUO Yuan-bo1,LIU Chun-hui2,LI Tao1   

  1. (Cryptography Engineering Institute, Information Engineering University, Zhengzhou 450001, China)1;
    (Unit 61213 of The Chinese People’s Liberation Army, Linfen, Shanxi 041000, China)2
  • Received:2019-02-28 Online:2020-03-15 Published:2020-03-30
  • About author:ZHONG Ya,born in 1995,postgra-duate.Her main research interests include insider threat detection and anomaly detection. GUO Yuan-bo,born in 1975,Ph.D,professor,is member of China Computer Federation.His main research interests include network attack and defense confrontation.
  • Supported by:
    This work was supported by the National Natural Science Foundation of China (61501515).

Abstract: With the widely use of information technology and Internet technology in enterprise organizations,enterprise information security faces unprecedented challenges.Most companies are faced with both external and internal attacks.Due to the lack of timely and effective detection methods,the damage caused by internal attacks is more serious.As the conductor of malicious behaviors in organization and enterprise,human is the research object in insider threat detection.Aiming at the low correlation and low detection efficiency of the similar threat detection for the existing insider threat detection method,user attributes profiling method was proposed.In this paper,users in the organization were taken as the research subject,and the clustering and supervision of similar users were mainly studied.Firstly,the method of calculating the similarity of portraits is defined.Then,the ontology theory and tabular portrait method were used to integrate multiple factors,such as user personality,personality,past expe-rience,working status,and setbacks.Similar users are clustered and managed in group by improved K-Means method,achieving the purpose of joint supervision on potential malicious ones,which reduces the possibility of similar damage occurring.Experimental results show that the proposed method is feasible and makes a way to combat the insider threat.

Key words: Enterprise security, Insider threat, User profiling, Group management, Similarity calculation, K-Means

CLC Number: 

  • TP391




