基于多源数据的内部威胁检测技术综述

REVIEW OF INSIDER THREAT DETECTION TECHNIQUES BASED ON MULTI-SOURCE DATA

  • 摘要: 近年来,内部威胁事件呈上升趋势,内部网络安全面临巨大挑战,内部威胁检测技术作为一种有效手段开始被广泛关注和研究。该文从数据来源角度对内部威胁检测技术的发展进行分析和总结,对比不同来源数据的特点、在检测中发挥的作用以及针对该类型数据的检测方法。在此基础上,介绍当前被广泛研究的内部威胁数据集CERT-IT,并对基于该数据集的内部威胁检测方法进行分析比较,探讨内部威胁检测技术面临的挑战和未来的发展趋势。

     

    Abstract: In recent years, insider threat incidents are on the rise, insider network security is facing great challenges, insider threat detection technology begins to be widely concerned and is studied as an effective means. This paper analyzes and summarizes the development of insider threat detection technology from the perspective of data sources, and compares the characteristics of data from different sources, the roles played in the detection and the detection methods for this type of data. On this basis, the paper introduced the widely studied insider threat dataset CERT-IT, and analyzed and compared the insider threat detection methods based on CERT-IT, so as to discuss the challenges faced by the current insider threat detection technology and the future development trend.

     

/

返回文章
返回