inklap

DEEP LEARNING MODEL FOR PREDICTING COMPROMISED ACCOUNTS IN SECURITY EVENT MANAGEMENT SYSTEMS

Yevhen Zhyvylo, Yurii Kuchma · Cybersecurity: Education, Science, Technique · 2025

In modern corporate information systems, the frequency of complex attacks aimed at compromising user accounts is increasing. Traditional security event management systems, based on correlation rules and signature analysis, demonstrate limited ability to predict potential incidents, as they do not account for temporal dependencies and user behavioral patterns. In this regard, the application of deep learning models capable of reproducing nonlinear relationships between authentication parameters and the probability of account compromise becomes relevant. This paper proposes a Deep Learning model for predicting compromise risk, built on a recurrent neural network of the LSTM type with an attention mechanism, which allows dynamic determination of the weight of temporal features in sequences of authentication events. The problem formalization involves minimizing a loss function that reflects the difference between the predicted probability of compromise and the actual state of the account. This approach increases the accuracy of anomaly detection and contributes to the construction of adaptive behavioral analytics within SIEM/UEBA architectures. The model implements the compromise risk

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً