A Method for Modeling Normal User Behavior Based on Security Risk Audit Elements

Yuke Wang, Guishan Dong, Jian Bai, Sha Deng, Dong Tang, Shigang Liu · 2024

In the field of data security audit, most current studies are confined to specific data sources, which are diverse and span across various industries. The heterogeneity of data sources results in significant differences in the generated audit data, thus impacting the cross-source reuse of audit methods. Furthermore, although progress has been made by these studies, there are still shortcomings in terms of audit comprehensiveness and coverage. To address these issues, this paper constructs a library of security risk audit elements to standardize the data processing of different sources, generating high-quality audit data that can cover a wider range of risk scenarios. The improvement in audit scenario coverage is shown through comparative analysis. Additionally, this paper also demonstrates a method for modeling normal user behavior with this library. Using the k-means algorithm, user behavior data from the Confluence backend was clustered. The clustering results, defined artificially, closely matched users' normal habits, proving the effectiveness of our elements-based method for modeling normal user behavior.

Read the paper · More papers on PaperTik