Insider Threats Detection Using CNN-LSTM Model
Ahmed Saaudi, Zaid Alibadi, Yan Tong, Csilla Farkas · 2018
Malicious insider activities threaten various govern-ment agencies and private organizations. This paper presents a novel approach to detect malicious behaviors. We propose the use of a granularity level to represent users' log data: textual session-based data samples. The user's behaviors are modeled using character embeddings and a deep learning model that consists of CNN and LSTM. Character embeddings are used to represent the input samples. Then, a convolution layer is used to capture local tri-gram features from the input samples, followed by an LSTM layer to consider the order of these given features (tri-grams). We conduct experiments using several variations of model architectures with no handcrafted features. The proposed model is evaluated with a subset of CERT Insider Threat dataset, r4.2. The result shows that performance improved with high precision and recall values.