Multi-Dimensional Anomalous Entity Detection via Poisson Tensor Factorization

dc.contributor.authorEren, Maksim E.
dc.contributor.authorMoore, Juston S.
dc.contributor.authorAlexandro, Boian S.
dc.date.accessioned2021-01-04T21:38:01Z
dc.date.available2021-01-04T21:38:01Z
dc.date.issued2020-12-08
dc.description2020 IEEE International Conference on Intelligence and Security Informatics (ISI)en_US
dc.description.abstractAs the attack surfaces of large enterprise networks grow, anomaly detection systems based on statistical user behavior analysis play a crucial role in identifying malicious activities. Previous work has shown that link prediction algorithms based on non-negative matrix factorization learn highly accurate predictive models of user actions. However, most statistical link prediction models have been constructed on bipartite graphs, and fail to capture the nuanced, multi-faceted details of a user’s activity profile. This paper establishes a new benchmark for red team event detection on the Los Alamos National Laboratory Unified Host and Network Dataset by applying a tensor factorization model that exploits the multi-dimensional and sparse structure of user authentication logs. We show that learning patterns of normal activity across multiple dimensions in one unified statistical framework yields improved detection of penetration testing events. We further show operational value by developing fusion methods that can identify anomalous users, source devices, and destination devices in the network.en_US
dc.description.sponsorshipWe thank Lissa Moore for helpful suggestions and edits, and Francesco Sanna Passino and Melissa Turcotte for providing valuable feedback and shared attribute mappings. Research presented in this paper was supported by the Information Science and Technology Institute’s CyberToaster Research school, and by the Laboratory Directed Research and Development program of Los Alamos National Laboratory (LANL) under project numbers 20190020DR and 20200666DI. LANL is operated by Triad National Security, LLC, for the National Nuclear Security Administration of the U.S. Department of Energy (Contract No. 89233218CNA000001).en_US
dc.description.urihttps://ieeexplore.ieee.org/abstract/document/9280524en_US
dc.format.extent6 pagesen_US
dc.genreconference papers and proceedingsen_US
dc.identifierdoi:10.13016/m2l0a5-sp8r
dc.identifier.citationEren, Maksim E.; Moore, Juston S.; Alexandro, Boian S.; Multi-Dimensional Anomalous Entity Detection via Poisson Tensor Factorization; 2020 IEEE International Conference on Intelligence and Security Informatics (ISI); https://ieeexplore.ieee.org/abstract/document/9280524en_US
dc.identifier.urihttps://doi.org/10.1109/ISI49825.2020.9280524
dc.identifier.urihttp://hdl.handle.net/11603/20287
dc.language.isoen_USen_US
dc.publisherIEEEen_US
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Computer Science and Electrical Engineering Department Collection
dc.relation.ispartofUMBC Student Collection
dc.rightsThis item is likely protected under Title 17 of the U.S. Copyright Law. Unless on a Creative Commons license, for uses protected by Copyright Law, contact the copyright holder or the author.
dc.rightsPublic Domain Mark 1.0*
dc.rightsThis work was written as part of one of the author's official duties as an Employee of the United States Government and is therefore a work of the United States Government. In accordance with 17 U.S.C. 105, no copyright protection is available for such works under U.S. Law.
dc.rights.urihttp://creativecommons.org/publicdomain/mark/1.0/*
dc.titleMulti-Dimensional Anomalous Entity Detection via Poisson Tensor Factorizationen_US
dc.typeTexten_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
09280524.pdf
Size:
2.42 MB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
2.56 KB
Format:
Item-specific license agreed upon to submission
Description: