A Hybrid Intelligent System for Insider Threat Detection Using Iterative Attention
Xueshuang Ren, Liming Wang · 2020
Insider threat is a severe security risk that tends to cause enormous financial losses and damages for organizations. Many approaches have been proposed to detect and mitigate insider threat. However, implementing an effective detection system is still a challenging task. In this paper, we propose a hybrid intelligent system for insider threat detection that aims to realize more effective detection of security incidents by incorporating multiple complementary detection techniques, such as entity portrait, rule matching and iterative attention. The system takes as input multi-domain heterogeneous event logs, psychological data and functional information that are available in the targeted organization. With both consideration of subjective and objective factors, the proposed system captures comprehensive information of events by building entity portraits. Subsequently, we perform insider threat detection by rule matching and iterative attention that can not only quickly detect known attacks but can also identify stealthy malicious activities at an early stage. We evaluated the proposed system using the CERT r4.2 insider threat dataset. Experimental results show that the hybrid intelligent system achieves a significant improvement compared with the state-of-the-art detection approach in terms of AUC and early detection scores.