BEAM: An Anomaly-Based Threat Detection System for Enterprise Multi-Domain Data
Derek Lin, Anying Li, Ryan Foltz · 2020
Organizations are faced with the ever-increasing risk of security threats. Security threats are multifaceted and present different levels of challenges to the defenders. While traditional deterministic signature and correlation-based methods serve limited purpose, behavior-based anomaly detection methods are best suited for identifying signature-less threats such as those from external adversary or insider activities. Challenges in building an anomaly detection system for enterprise security are numerous. This paper introduces a new anomaly detection system that addresses the feature engineering process for multi-domain data in enterprises and provides a Bayes-based risk scoring method for information fusion. The system is adaptive to dynamic user and network behaviors and produces interpretable outcomes by design. To perform quantitative evaluation against a baseline system without known labeled attack data, we propose a method to synthesize the ground truth to demonstrate the improvement in detection performance.