Insider Threat Detection Using Generative Adversarial Graph Attention Networks
Chaoyang Li, Fenghua Li, Mingjie Yu, Yunchuan Guo, Yitong Wen, Zifu Li · GLOBECOM 2022 - 2022 IEEE Global Communications Conference · 2022
Insiders cause serious security threats to organizations. Existing insider threat detection methods mainly mine the users' behaviors or psychological features by analyzing the users' operation logs, and they ignore the associations of behaviors among users and get unappealing performance on the imbalanced samples. In this paper, considering attention mechanism, we propose Generative Adversarial Graph Attention Networks (GAGAN) to detect insider threats. First, we design association rules to construct a graph to associate users' behaviors. Second, to address the imbalanced samples, we adopt graph generator to generate abnormal nodes; A discriminator with graph attention networks is designed to further mine the potential associations of behaviors among users and discriminate real nodes from the generated nodes, also adopted to discriminate anomaly nodes from normal nodes. Experimental results on CERT data set demonstrate that our method can accurately detect abnormal insiders and outperforms several state-of-the-art baseline methods.