Abstract

AbstractIn the User and Entity Behaviour Analytics (UEBA), unknown malicious behaviours are often difficult to be automatically detected due to the lack of labelled data. Most of the existing methods also fail to take full advantage of the threat intelligence and incorporate the impact of the behaviour patterns of the benign users. To address this issue, this paper proposes a Generalised Zero‐Shot Learning (GZSL) method based on hyper‐spherical Variational Auto‐Encoders (VAEs). Compared to the VAEs, the authors’ proposed method is more robust and suitable for capturing data with richer and more nuanced structures. The authors’ method analyses the unknown malicious behaviours by projecting them and their semantic attributes to shared space. These are then matched by the cosine similarity. The authors further use a Graph Convolutional Network (GCN) to reduce the impact of different user behaviour patterns before projection. The experimental results indicate that the proposed method is efficient in the analysis of unknown malicious behaviours.

Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.