Title :
Using Consensus Clustering for Multi-view Anomaly Detection
Author :
Liu, Alan Y. ; Lam, D.N.
Author_Institution :
Appl. Res. Labs., Univ. of Texas at Austin, Austin, TX, USA
Abstract :
This paper presents work on automatically characterizing typical user activities across multiple sources (or views) of data, as well as finding anomalous users who engage in unusual combinations of activities across different views of data. This approach can be used to detect malicious insiders who may abuse their privileged access to systems in order to accomplish goals that are detrimental to the organizations that grant those privileges. To avoid detection, these malicious insiders want to appear as normal as possible with respect to the activities of other users with similar privileges and tasks. Therefore, given a single type or view of audit data, the activities of the malicious insider may appear normal. An anomaly may only be apparent when analyzing multiple sources of data. We propose and test domain-independent methods that combine consensus clustering and anomaly detection techniques. We benchmark the efficacy of these methods on simulated insider threat data. Experimental results show that combining anomaly detection and consensus clustering produces more accurate results than sequentially performing the two tasks independently.
Keywords :
authorisation; organisational aspects; pattern clustering; consensus clustering; domain-independent methods; malicious insiders; multiple data sources; multiview anomaly detection; organizations; simulated insider threat data; user activities; Clustering algorithms; Data mining; Data models; Databases; Measurement; Mutual information; Semantics; anomaly detection; consensus clustering; insider threat; multi-view learning;
Conference_Titel :
Security and Privacy Workshops (SPW), 2012 IEEE Symposium on
Conference_Location :
San Francisco, CA
Print_ISBN :
978-1-4673-2157-0
DOI :
10.1109/SPW.2012.18