Insider Threat Detection based on Knowledge Graph and Large Language Model
Yingna Li, Zhiguo Ding, Zheng Yan, Zuoqiang Li, Hang Shao · 2024
This article proposes an insider threat detection method based on a combination of knowledge graph and large language model (LLM); first, the internal systems, users, IPs, access behaviors, etc. are modeled through the knowledge graph ontology; then, a few-shot learning information extraction method based on LLMs is used to extract knowledge from the behavior logs to complete the threat detection knowledge graph. Finally, the representation learning method based on the knowledge graph and the embedding based on the LLM are used to extract feature vectors, which are used as input of the insider threat detection model training based on Deep SVDD. The experimental results show that this method can automatically detect abnormal threat behaviors from massive logs at high accuracy, and has the ability to detect deeply hidden abnormal threat behaviors.