PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
November 1, 2018International Journal of Software Engineering and Knowledge Engineering10 citations

An Ensemble Approach for Detecting Anomalous User Behaviors

View Full Paper
XXXiangyu XiMacau University of Science and TechnologyTZTong ZhangKing UniversityWYWei YeState Grid Corporation of China (China)

Key Points

Key points are not available for this paper at this time.

Abstract

An intruder of a company’s network may use stolen login credentials to silently collect sensitive data. Such malicious user behavior is difficult to detect as long as it does not trigger access violation or data leak alert. In this paper, we propose to use an ensemble of three unsupervised anomaly detection algorithms, namely OCSVM, RNN and Isolation Forest, to detect abnormal user behavior patterns. Besides, an User Behavior Analytics (UBA) Platform is proposed to collect logs, extract features and conduct experiments. The experiment results indicate that our algorithm outperforms each individual algorithm with recall of 96.55% and precision of 91.24% on average, while both OCSVM and RNN suffer from anomalies in the training set, and Formula: see text produces more false positives and false negatives in prediction.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Xi et al. (2018) studied this question.

synapsesocial.com/papers/6a12cd99c031bb6829a75411https://doi.org/10.1142/s0218194018400211
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1LIBSVM2011 · 41,430 citations
  2. 2Plastic card fraud detection using peer group analysis2008 · 88 citations
  3. 3An ensemble learning framework for anomaly detection in building energy consumption2017 · 257 citations
  4. 4A survey of anomaly detection techniques in financial domain2015 · 523 citations
  5. 5The CERT Guide to Insider Threats: How to Prevent, Detect, and Respond to Information Technology Crimes2012 · 176 citations