Viability of novel insider threat detection framework on augmented real-world and simulated datasets

Over the past few years, Insider threats have been a growing concern for the organizations. The concerns have arisen due to the reported cases of insider activities damages that have far out weighted the damaged caused by external factors. This have led to many studies that have been performed in at...

Full description

Saved in:
Bibliographic Details
Main Author: Xiong Tian
Other Authors: Chen Lihui
Format: Theses and Dissertations
Language:English
Published: 2019
Subjects:
Online Access:http://hdl.handle.net/10356/78826
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Nanyang Technological University
Language: English
id sg-ntu-dr.10356-78826
record_format dspace
spelling sg-ntu-dr.10356-788262023-07-04T16:37:12Z Viability of novel insider threat detection framework on augmented real-world and simulated datasets Xiong Tian Chen Lihui School of Electrical and Electronic Engineering Engineering::Electrical and electronic engineering Over the past few years, Insider threats have been a growing concern for the organizations. The concerns have arisen due to the reported cases of insider activities damages that have far out weighted the damaged caused by external factors. This have led to many studies that have been performed in attempt to identify insider threats. However, despite the widespread interest, organizations that have experienced insider threats are often reluctant to share the relevant data for further research studies. Recently, a novel insider threat detection framework which attempts to identify potential insider threats by building employee profiles based on the observed aspect-based sentiments in their emails was proposed. However, there is no available real-world email corpus with insider threat scenario that can be used to appropriately evaluate the feasibility of the framework. In this work, the working mechanism of the framework is first analysed and understood. Following that, the framework is applied on two different synthetic datasets namely, TWOS and Enron plus. Then in-depth analysis is performed on the results to estimate the viability of the framework in the real-world. When we applied the simulation dataset TWOS to insider threat detection framework, we found that the emotion polarity can correspond to three classical psychological behaviour theories. Then by comparing the accuracy obtained from TWOS and Enron plus, we further analysed the performance of the model on different datasets. Also, by analysing the difference between the actual situation and the results from the anomaly detection, it shows that anomaly detection results based on some aspects can agree with reality, but others cannot evaluate the user performance. Therefore, we believe that irrelevant aspects may limit the detection capabilities of the insider threat detection framework. Master of Science (Signal Processing) 2019-07-02T02:11:54Z 2019-07-02T02:11:54Z 2019 Thesis http://hdl.handle.net/10356/78826 en 66 p. application/pdf
institution Nanyang Technological University
building NTU Library
continent Asia
country Singapore
Singapore
content_provider NTU Library
collection DR-NTU
language English
topic Engineering::Electrical and electronic engineering
spellingShingle Engineering::Electrical and electronic engineering
Xiong Tian
Viability of novel insider threat detection framework on augmented real-world and simulated datasets
description Over the past few years, Insider threats have been a growing concern for the organizations. The concerns have arisen due to the reported cases of insider activities damages that have far out weighted the damaged caused by external factors. This have led to many studies that have been performed in attempt to identify insider threats. However, despite the widespread interest, organizations that have experienced insider threats are often reluctant to share the relevant data for further research studies. Recently, a novel insider threat detection framework which attempts to identify potential insider threats by building employee profiles based on the observed aspect-based sentiments in their emails was proposed. However, there is no available real-world email corpus with insider threat scenario that can be used to appropriately evaluate the feasibility of the framework. In this work, the working mechanism of the framework is first analysed and understood. Following that, the framework is applied on two different synthetic datasets namely, TWOS and Enron plus. Then in-depth analysis is performed on the results to estimate the viability of the framework in the real-world. When we applied the simulation dataset TWOS to insider threat detection framework, we found that the emotion polarity can correspond to three classical psychological behaviour theories. Then by comparing the accuracy obtained from TWOS and Enron plus, we further analysed the performance of the model on different datasets. Also, by analysing the difference between the actual situation and the results from the anomaly detection, it shows that anomaly detection results based on some aspects can agree with reality, but others cannot evaluate the user performance. Therefore, we believe that irrelevant aspects may limit the detection capabilities of the insider threat detection framework.
author2 Chen Lihui
author_facet Chen Lihui
Xiong Tian
format Theses and Dissertations
author Xiong Tian
author_sort Xiong Tian
title Viability of novel insider threat detection framework on augmented real-world and simulated datasets
title_short Viability of novel insider threat detection framework on augmented real-world and simulated datasets
title_full Viability of novel insider threat detection framework on augmented real-world and simulated datasets
title_fullStr Viability of novel insider threat detection framework on augmented real-world and simulated datasets
title_full_unstemmed Viability of novel insider threat detection framework on augmented real-world and simulated datasets
title_sort viability of novel insider threat detection framework on augmented real-world and simulated datasets
publishDate 2019
url http://hdl.handle.net/10356/78826
_version_ 1772827513694715904