Agrupamento de usuários e organizações para verificação de viabilidade de distinção comportamental de uso de sistemas com base em aplicações e tempo

Marcelo Marques Ribas, Ulisses Penteado, Andre Ricardo Abed Gregio, Paulo Ricardo Lisboa de Almeida · Anais do Computer on the Beach · 2025

Authentication mechanisms are still the standard way to allowaccess to systems and devices within an organization. Throughcredentials (login and password) and other associated methods(multi-factor authentication, such as tokens, biometrics, or onetimepasswords sent to additional devices), access control is implemented,and user activity across different necessary systems isrecorded. However, organizations are concerned that access controlmay be bypassed due to the loss or theft of authentication information/devices, potentially leading to intellectual property breachesthrough industrial espionage. In this context, User and Entity BehaviorAnalytics (UEBA) has been studied and applied to profile usersand identify anomalous patterns that could, for example, block auser from accessing another account. However, achieving this levelof protection in real-world systems may be unfeasible. This articleexamines the feasibility of distinguishing user behavior in organizationsbased on the most frequently used applications and theirusage time. To this end, a real dataset was collected, consisting ofdata from over 700 organizations and nearly 60,000 users betweenMarch and September 2024. The results discuss the techniques used,the possibility of detecting real intruder users, and the false alarmrates observed in the dataset, paving the way for future research inthe field.

Read the paper · More papers on PaperTik