A Scalable Cybersecurity Framework for Anomaly Detection in User Behaviour

Research Square (Research Square)(2022)

引用 0|浏览0
暂无评分
摘要
Abstract Nowadays, the speed of the user and application logs is so quick that it is almost impossible to analyse them in real-time without using scalable systems and platforms. In cybersecurity, human behaviour is responsible directly or indirectly for the most common attacks (i.e., ransomware and phishing). To monitor user behaviour, it is necessary to process fast user logs coming from different and heterogeneous sources, having part of the data or some entire sources missing. A scalable framework based on the Elastic Stack (ELK) to process and store log data from different users and applications is proposed for this aim. This system generates an ensemble of models to classify user behaviour and detect anomalies in real-time. The scalability of the system is guaranteed by the ELK-based software architecture, running on top of a Kubernetes platform. In addition, a distributed evolutionary algorithm is used to classify the users by exploiting their digital footprints derived from many data sources. Experiments conducted on two real-life datasets verify the approach's goodness in detecting anomalies in the user behaviour, coping with missing data and lowering the number of false alarms.
更多
查看译文
关键词
scalable cybersecurity framework,anomaly detection,user behaviour
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要