Abstract Insiders threats typically originate from authorized personnel who are familiar with the organization’s insider security measures. They typically hide within vast amounts of normal operational logs, characterized by their covert nature, complexity, and diversity. These attributes make insider threat detection one of the most challenging tasks in cybersecurity protection for enterprises and organizations. Current methods for insider threat detection primarily fall into two categories: traditional machine learning methods and deep learning methods. Machine learning methods typically rely on feature engineering to extract features, which are then processed by shallow models. Deep learning methods typically operate by either feeding user feature vectors into neural networks or by analyzing chronological behavior sequences from user logs with time series models to detect insider threats. However, existing methods frequently ignore the multi-scale periodicity inherent in user behaviors and do not adequately leverage absolute timestamp data from logs. Furthermore, they typically categorize behaviors coarsely as normal or anomalous, which fails to achieve precise
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً