A comprehensive investigation of clustering algorithms for User and Entity Behavior Analytics

被引:2
|
作者
Artioli, Pierpaolo [1 ]
Maci, Antonio [1 ]
Magri, Alessio [1 ]
机构
[1] BV TECH SpA, Cybersecur Lab, Milan, Italy
来源
FRONTIERS IN BIG DATA | 2024年 / 7卷
关键词
clustering; data analytics; machine learning; UEBA; unsupervised learning; BIG DATA;
D O I
10.3389/fdata.2024.1375818
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Introduction Government agencies are now encouraging industries to enhance their security systems to detect and respond proactively to cybersecurity incidents. Consequently, equipping with a security operation center that combines the analytical capabilities of human experts with systems based on Machine Learning (ML) plays a critical role. In this setting, Security Information and Event Management (SIEM) platforms can effectively handle network-related events to trigger cybersecurity alerts. Furthermore, a SIEM may include a User and Entity Behavior Analytics (UEBA) engine that examines the behavior of both users and devices, or entities, within a corporate network.Methods In recent literature, several contributions have employed ML algorithms for UEBA, especially those based on the unsupervised learning paradigm, because anomalous behaviors are usually not known in advance. However, to shorten the gap between research advances and practice, it is necessary to comprehensively analyze the effectiveness of these methodologies. This paper proposes a thorough investigation of traditional and emerging clustering algorithms for UEBA, considering multiple application contexts, i.e., different user-entity interaction scenarios.Results and discussion Our study involves three datasets sourced from the existing literature and fifteen clustering algorithms. Among the compared techniques, HDBSCAN and DenMune showed promising performance on the state-of-the-art CERT behavior-related dataset, producing groups with a density very close to the number of users.
引用
收藏
页数:25
相关论文
共 50 条
  • [1] User and Entity Behavior Analytics for Enterprise Security
    Shashanka, Madhu
    Shen, Min-Yi
    Wang, Jisheng
    2016 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2016, : 1867 - 1874
  • [2] Reducing False Positives Of User-to-Entity First-Access Alerts for User Behavior Analytics
    Tang, Baoming
    Hu, Qiaona
    Lin, Derek
    2017 17TH IEEE INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS (ICDMW 2017), 2017, : 804 - 811
  • [3] A User and Entity Behavior Analytics Log Data Set for Anomaly Detection in Cloud Computing
    Landauer, Max
    Skopik, Florian
    Hold, Georg
    Wurzenberger, Markus
    Proceedings - 2022 IEEE International Conference on Big Data, Big Data 2022, 2022, : 4285 - 4294
  • [4] Scalable Data Processing Approach and Anomaly Detection Method for User and Entity Behavior Analytics Platform
    Lukashin, Alexey
    Popov, Mikhail
    Bolshakov, Anatoliy
    Nikolashin, Yuri
    INTELLIGENT DISTRIBUTED COMPUTING XIII, 2020, 868 : 344 - 349
  • [5] Deep Belief Network-Based User and Entity Behavior Analytics (UEBA) for Web Applications
    Deepa, S.
    Umamageswari, A.
    Neelakandan, S.
    Bhukya, Hanumanthu
    Haritha, I. V. Sai Lakshmi
    Shanbhog, Manjula
    INTERNATIONAL JOURNAL OF COOPERATIVE INFORMATION SYSTEMS, 2024, 33 (02)
  • [6] A Comprehensive Survey of Clustering Algorithms
    Dongkuan Xu
    Yingjie Tian
    Annals of Data Science, 2015, 2 (2) : 165 - 193
  • [7] Multi-homed abnormal behavior detection algorithm based on fuzzy particle swarm cluster in user and entity behavior analytics
    Jingyang Cui
    Guanghua Zhang
    Zhenguo Chen
    Naiwen Yu
    Scientific Reports, 12
  • [8] Multi-homed abnormal behavior detection algorithm based on fuzzy particle swarm cluster in user and entity behavior analytics
    Cui, Jingyang
    Zhang, Guanghua
    Chen, Zhenguo
    Yu, Naiwen
    SCIENTIFIC REPORTS, 2022, 12 (01)
  • [9] Comparison of Clustering Algorithms for Learning Analytics with Educational Datasets
    Martinez Navarro, Alvaro
    Moreno-Ger, Pablo
    INTERNATIONAL JOURNAL OF INTERACTIVE MULTIMEDIA AND ARTIFICIAL INTELLIGENCE, 2018, 5 (02): : 9 - 16
  • [10] Different Clustering Algorithms for Big Data Analytics: A Review
    Dave, Meenu
    Gianey, Hemant
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON SYSTEM MODELING & ADVANCEMENT IN RESEARCH TRENDS (SMART-2016), 2016, : 328 - 333