In modern corporate information systems, a significant proportion of information security incidents are insider threats. This creates new requirements for security event monitoring and analysis systems. Unlike external attacks, insider activity is disguised as the usual work of legitimate users, and therefore is difficult to describe using classic signature or perimeter protection mechanisms. An additional complexity is the extreme imbalance of classes in event logs. The number of records of typical daily activity is thousands of times higher than the number of recorded incidents. This leads to degradation of the quality of standard machine learning algorithms. The article develops an approach to increasing the efficiency of detecting insider threats by augmenting data using generative adversarial networks, in particular the Conditional Tabular GAN (CTGAN) architecture. A process for preparing behavioral logs is proposed. This process involves the aggregation of multi-channel events to the "user-day" level, construction of a vector of dynamic behavioral features and static context, logarithmic normalization of features with "heavy tails" and scaling to the range [–1; 1]. This ensu
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً