Literature DB >> 25621314

Leveraging Social Networks to Detect Anomalous Insider Actions in Collaborative Environments.

You Chen1, Steve Nyemba2, Wen Zhang, Bradley Malin.   

Abstract

Collaborative information systems (CIS) enable users to coordinate efficiently over shared tasks. T hey are often deployed in complex dynamic systems that provide users with broad access privileges, but also leave the system vulnerable to various attacks. Techniques to detect threats originating from beyond the system are relatively mature, but methods to detect insider threats are still evolving. A promising class of insider threat detection models for CIS focus on the communities that manifest between users based on the usage of common subjects in the system. However, current methods detect only when a user's aggregate behavior is intruding, not when specific actions have deviated from expectation. In this paper, we introduce a method called specialized network anomaly detection (SNAD) to detect such events. SNAD assembles the community of users that access a particular subject and assesses if similarities of the community with and without a certain user are sufficiently different. We present a theoretical basis and perform an extensive empirical evaluation with the access logs of two distinct environments: those of a large electronic health record system (6,015 users, 130,457 patients and 1,327,500 accesses) and the editing logs of Wikipedia (2,388,955 revisors, 55,200 articles and 6,482,780 revisions). We compare SNAD with several competing methods and demonstrate it is significantly more effective: on average it achieves 20-30% greater area under an ROC curve.

Entities:  

Year:  2011        PMID: 25621314      PMCID: PMC4303584          DOI: 10.1109/ISI.2011.5984061

Source DB:  PubMed          Journal:  ISI


  4 in total

1.  Learning relational policies from electronic health record access logs.

Authors:  Bradley Malin; Steve Nyemba; John Paulett
Journal:  J Biomed Inform       Date:  2011-01-26       Impact factor: 6.317

2.  Can electronic medical record systems transform health care? Potential health benefits, savings, and costs.

Authors:  Richard Hillestad; James Bigelow; Anthony Bower; Federico Girosi; Robin Meili; Richard Scoville; Roger Taylor
Journal:  Health Aff (Millwood)       Date:  2005 Sep-Oct       Impact factor: 6.301

Review 3.  Reviewing the benefits and costs of electronic health records and associated patient safety technologies.

Authors:  Nir Menachemi; Robert G Brooks
Journal:  J Med Syst       Date:  2006-06       Impact factor: 4.460

4.  Detection of Anomalous Insiders in Collaborative Environments via Relational Analysis of Access Logs.

Authors:  You Chen; Bradley Malin
Journal:  CODASPY       Date:  2011
  4 in total
  4 in total

1.  Detecting Anomalous Insiders in Collaborative Information Systems.

Authors:  You Chen; Steve Nyemba; Bradley Malin
Journal:  IEEE Trans Dependable Secure Comput       Date:  2012-05       Impact factor: 7.329

2.  Work-Based Access Control Model for Cooperative Healthcare Environments: Formal Specification and Verification.

Authors:  Mohamed Abomhara; Huihui Yang; Geir M Køien; Mehdi Ben Lazreg
Journal:  J Healthc Inform Res       Date:  2017-05-22

3.  Specializing network analysis to detect anomalous insider actions.

Authors:  You Chen; Steve Nyemba; Wen Zhang; Bradley Malin
Journal:  Secur Inform       Date:  2012-02-27

4.  Apache Spark and Deep Learning Models for High-Performance Network Intrusion Detection Using CSE-CIC-IDS2018.

Authors:  Abdulnaser A Hagar; Bharti W Gawali
Journal:  Comput Intell Neurosci       Date:  2022-08-26
  4 in total

北京卡尤迪生物科技股份有限公司 © 2022-2023.