Netinfo Security ›› 2017, Vol. 17 ›› Issue (3): 27-32.doi: 10.3969/j.issn.1671-1122.2017.03.005

• Orginal Article • Previous Articles     Next Articles

Research on Insider Threat Detection Based on Role Behavior Pattern Mining

Dianwei LI1, Mingliang HE2(), Fang YUAN3   

  1. 1. Naval Staff, Beijing 100841, China
    2. No.92529 Troops of PLA, Taizhou Zhejiang 317600, China
    3. Information Security Department, Naval University of Engineering, Wuhan Hubei 430033, China
  • Received:2016-12-15 Online:2017-03-20 Published:2020-05-12

Abstract:

Aiming at the problem that the internal threat of information system is difficult be detected, this paper combined access control and data mining, design an internal threat detection model based on role behavior pattern mining. This paper proposes an internal threat warning method based on user roles code of conduct, behavior habit and actual operation behavior matching. Each operation personnel in information systems and operations management personnel have their own responsibility. Performance is the individual users in the system application have its own role, and each role has its own code of conduct and behavior. The method in this paper is to extract the user behavior habit and daily operation from the system log and the application software log by using the data mining technology according to the system specification, and achieves the internal threat warning by detecting the deviation degree from the actual behavior and user roles code of conduct and the behavior habit.

Key words: information system, role, behavior patterns, data mining, threat detection

CLC Number: