Design and Implementation of Cyber Space Threat Detection System Based on User Behavioral Logs

Wenhao Wang, Hao Li, Peng Nie · 2023

In contemporary society, the role of networks in daily work and business activities is increasingly prominent. The enterprise intranet, serving as a crucial bridge for maintaining work stability, asset security, and business continuity, has garnered significant attention from both academia and industry in the field of intranet security detection. This study is based on the Log2Vec algorithm and involves the design and implementation of a Cyber Space Threat Detection System. The system, facilitated by the collaborative efforts of three modules— log ingestion, graph encoding, and security detection—effectively showcases user behavior, encodes logs into a heterogeneous graph, transforms the graph into vectors, and conducts cluster analysis to detect abnormal user behavior. Through in-depth research and systematic design, this study aims to provide enterprises with a more advanced and comprehensive intranet security detection solution to cope with evolving cybersecurity threats.

Read the paper · More papers on PaperTik