Developing Cyber-Personas from Syslog Files for Insider Threat Detection: A Feasibility Study

Kevin Purcell, Sridhar Reddy Ravula, Ziyuan Huang, Mark Newman, Joshua Rykowski, Kevin L. Huggins · Auerbach Publications eBooks · 2018

This chapter aims to explore the potential of using unprocessed system logs to develop and monitor cyber-personas. System logs are a standard for network message logging. Each system log (syslog) message contains a wealth of information including severity labels and facility codes that indicate the message-generating software. The syslog standard is used in a variety of devices including printers, routers, and message receivers across platforms over many operating systems. To validate the concept of using data-driven personas as a system for insider threat identification and management, the chapter explores a two-stage process that includes constructing date-driven user personas and then employing these models to identifying behavioral deviations of network users. To explore the feasibility of applying the data-driven persona theory to threat identification, one had to understand the extent to which syslogs could serve as a rich resource for network user behavior.

Read the paper · More papers on PaperTik