DocumentCode
3127705
Title
Unsupervised incremental sequence learning for insider threat detection
Author
Parveen, Pallabi ; Thuraisingham, Bhavani
Author_Institution
Dept. of Comput. Sci., Univ. of Texas at Dallas, Dallas, TX, USA
fYear
2012
fDate
11-14 June 2012
Firstpage
141
Lastpage
143
Abstract
Insider threat detection requires the identification of rare anomalies in contexts where evolving behaviors tend to mask such anomalies. This paper proposes and tests an incremental learning algorithm based on unsupervised learning that addresses this challenge by maintaining repetitive sequences in a compressed dictionary to identify anomaly over dynamic data streams of unbounded length. For unsupervised learning, compression-based techniques are used to model normal behavior sequences. The result is a classifier that exhibits substantially increased classification accuracy for insider threat streams relative to traditional static learning approaches and effectiveness over supervised learning approaches.
Keywords
security of data; unsupervised learning; anomaly identification; compression based techniques; dynamic data streams; incremental learning algorithm; insider threat detection; supervised learning; unbounded length; unsupervised incremental sequence learning; Data mining; Dictionaries; Educational institutions; Supervised learning; Training; Training data; Unsupervised learning; Increment Learning; Insider threat Detection; Unsupervised Learning;
fLanguage
English
Publisher
ieee
Conference_Titel
Intelligence and Security Informatics (ISI), 2012 IEEE International Conference on
Conference_Location
Arlington, VA
Print_ISBN
978-1-4673-2105-1
Type
conf
DOI
10.1109/ISI.2012.6284271
Filename
6284271
Link To Document