A comprehensive investigation of clustering algorithms for User and Entity Behavior Analytics

被引:2
|
作者
Artioli, Pierpaolo [1 ]
Maci, Antonio [1 ]
Magri, Alessio [1 ]
机构
[1] BV TECH SpA, Cybersecur Lab, Milan, Italy
来源
FRONTIERS IN BIG DATA | 2024年 / 7卷
关键词
clustering; data analytics; machine learning; UEBA; unsupervised learning; BIG DATA;
D O I
10.3389/fdata.2024.1375818
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Introduction Government agencies are now encouraging industries to enhance their security systems to detect and respond proactively to cybersecurity incidents. Consequently, equipping with a security operation center that combines the analytical capabilities of human experts with systems based on Machine Learning (ML) plays a critical role. In this setting, Security Information and Event Management (SIEM) platforms can effectively handle network-related events to trigger cybersecurity alerts. Furthermore, a SIEM may include a User and Entity Behavior Analytics (UEBA) engine that examines the behavior of both users and devices, or entities, within a corporate network.Methods In recent literature, several contributions have employed ML algorithms for UEBA, especially those based on the unsupervised learning paradigm, because anomalous behaviors are usually not known in advance. However, to shorten the gap between research advances and practice, it is necessary to comprehensively analyze the effectiveness of these methodologies. This paper proposes a thorough investigation of traditional and emerging clustering algorithms for UEBA, considering multiple application contexts, i.e., different user-entity interaction scenarios.Results and discussion Our study involves three datasets sourced from the existing literature and fifteen clustering algorithms. Among the compared techniques, HDBSCAN and DenMune showed promising performance on the state-of-the-art CERT behavior-related dataset, producing groups with a density very close to the number of users.
引用
收藏
页数:25
相关论文
共 50 条
  • [41] News Recommendation Based on User Topic and Entity Preferences in Historical Behavior
    Zhang, Haojie
    Shen, Zhidong
    INFORMATION, 2023, 14 (02)
  • [42] Cyberattack Detection Framework Using Machine Learning and User Behavior Analytics
    Alshehri, Abdullah
    Khan, Nayeem
    Alowayr, Ali
    Alghamdi, Mohammed Yahya
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2023, 44 (02): : 1679 - 1689
  • [43] User Behavior Analytics in Virtual Training Environments for Sensory Substitution Devices
    Flamaropol, Daniel
    Moldoveanu, Alin
    Moldoveanu, Florica
    Dascalu, Maria-Iuliana
    Stanica, Iulia
    Negoi, Ionut
    2018 ZOOMING INNOVATION IN CONSUMER TECHNOLOGIES CONFERENCE (ZINC), 2018, : 22 - 26
  • [44] User Behavior Analytics with Machine Learning for Household Electricity Demand Forecasting
    Moon, Jihoon
    Kim, Yongsung
    Rho, Seungmin
    2022 INTERNATIONAL CONFERENCE ON PLATFORM TECHNOLOGY AND SERVICE (PLATCON22), 2022, : 13 - 18
  • [45] Integrating Modeling Languages and Web Logs for Enhanced User Behavior Analytics
    Bernaschina, Carlo
    Brambilla, Marco
    Koka, Thanas
    Mauri, Andrea
    Umuhoza, Eric
    WWW'17 COMPANION: PROCEEDINGS OF THE 26TH INTERNATIONAL CONFERENCE ON WORLD WIDE WEB, 2017, : 171 - 175
  • [46] Machine Learning and Event-Based User and Entity Behavior Analysis
    Onal, Vedat
    Arslan, Halil
    Gormez, Yasin
    32ND IEEE SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE, SIU 2024, 2024,
  • [47] Evaluation of data analytics based clustering algorithms for knowledge mining in a student engagement data
    Oladipupo, O. O.
    Olugbara, O. O.
    INTELLIGENT DATA ANALYSIS, 2019, 23 (05) : 1055 - 1071
  • [48] TOWARDS A COMPREHENSIVE FRAMEWORK FOR QOE AND USER BEHAVIOR MODELLING
    Reichl, Peter
    Egger, Sebastian
    Moeller, Sebastian
    Kilkki, Kalevi
    Fiedler, Markus
    Hossfeldb, Tobias
    Tsiaras, Christos
    Asrese, Alemnew
    2015 SEVENTH INTERNATIONAL WORKSHOP ON QUALITY OF MULTIMEDIA EXPERIENCE (QOMEX), 2015,
  • [49] Comprehensive investigation of the photophysical behavior of oligopolyfurans
    de Melo, JS
    Elisei, F
    Gartner, C
    Aloisi, GG
    Becker, RS
    JOURNAL OF PHYSICAL CHEMISTRY A, 2000, 104 (30): : 6907 - 6911
  • [50] A Comprehensive Complexity Analysis of User-level Memory Allocator Algorithms
    Ferreira, Tais Borges
    Fernandes, Marcia Aparecida
    Matias, Rivalino, Jr.
    2012 BRAZILIAN SYMPOSIUM ON COMPUTING SYSTEM ENGINEERING (SBESC 2012), 2012, : 99 - 104