Modeling behavior in a network using event logs
Melissa Turcotte · OSTI OAI (U.S. Department of Energy Office of Scientific and Technical Information) · 2023
A framework is provided for modeling the activity surrounding user credentials and/or machine level activity on a computer network using computer event logs by viewing the logs attributed to each user as a multivariate data stream. The methodology performs well in detecting compromised user credentials at a very low false positive rate. Such a methodology may detect both users of compromised credentials by external actors and otherwise authorized users who have begun engaging in malicious activity.