User Behaviour Risk Evaluation in Zero Trust Architecture Environment

Wawan Yunanto, Hsing-Kuo Pao · 2022

Our study proposes user access evaluation framework within the trustworthy organization network. We design a mechanism on how to measure user access risk on every interaction with the servers. It is an extensive anomaly detection problem where the already trusted user is continuously being observed while interacting with organization resources. Moreover, alongside with network perimeter based authentication, this study provides an improved access control to evaluate the risk of every user behavior in day-to-day operation. To portray user interaction with organization server, our work focus on user behavior risk evaluation using log entries recorded by Apache Web Server. We perform the log analysis process and develop an unsupervised recurrent deep neural net architecture which is widely used in recent log data anomaly detection for high performance computing and cloud computing infrastructure. This approach may perform well in previous use cases but its never been arranged for Apache Access log data. Unlike other log analysis datasets, ours has no label defined by domain expert, so we propose an alternative way to carry out and evaluate the experiments for User anomaly behaviour detection. Our method yields a good result on small log data and has a decent performance on large data. This is a very promising outcome in the early stage of User Behaviour Risk Evaluation.

Read the paper · More papers on PaperTik