全特征信息均衡建模的内部威胁人物检测

Translated title of the contribution: Full-featured information equalization modeling for insider threat detection

Yu Liu, Sen Lin Luo, Le Wei Qu, Li Min Pan*, Ji Zhang

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

2 Citations (Scopus)

Abstract

A method that used full-featured information equalization modeling for insider threat detection was proposed in view of the current problems of low accuracy of insider threat detection and incomplete utilization of high-dimensional data feature information. The features of the multi-source data generated within the organization were extracted and constructed. Then all the features were cross-grouped, and the cross-grouped features were used to construct the isolation forest model with improving the balance of the use of data feature information in the process of model building. The generated isolation forest model was used for insider threat detection. The experimental results show that the method has a higher F1 value on the CERT-IT (v4.2) insider threat figures data set, and the efficiency of the algorithm is high. The algorithm can be effectively used for insider threat detection.

Translated title of the contributionFull-featured information equalization modeling for insider threat detection
Original languageChinese (Traditional)
Pages (from-to)777-784
Number of pages8
JournalZhejiang Daxue Xuebao (Gongxue Ban)/Journal of Zhejiang University (Engineering Science)
Volume53
Issue number4
DOIs
Publication statusPublished - 1 Apr 2019

Fingerprint

Dive into the research topics of 'Full-featured information equalization modeling for insider threat detection'. Together they form a unique fingerprint.

Cite this