Stream Analytics for Insider Threat Detection
Bhavani Thuraisngham, Murat Kantarcıoğlu, Latifur R. Khan · 2022
Malicious insiders are perhaps the most potent threats to information assurance in many or most organizations. This chapter describes approach to insider threat detection using stream data mining for both non-sequence and sequence data. It provides a survey of insider threat and stream mining. The chapter also discuss scalability issues with big data/data science techniques. Supervised learning approaches collect system call trace logs containing records of normal and anomalous behavior extract n-gram features from the collected data, and use the extracted features to train classifiers. Recently unsupervised learning has been applied to detect insider threat in a data stream. Stream data are continuously coming with high velocity and large size. In summary, to cope with concept-evolution, a supervised approach maintains an evolving ensemble of multiple OCSVM models. In particular, scalability is an issue for constructing benign pattern sequences for quantized dictionary.