利用深度学习为零信任安全基础设施建立异常行为检测机制

Hyun-Woo Kim, Eun-Ha Song
{"title":"利用深度学习为零信任安全基础设施建立异常行为检测机制","authors":"Hyun-Woo Kim, Eun-Ha Song","doi":"10.1007/s41870-024-02110-7","DOIUrl":null,"url":null,"abstract":"<p>As ICT technology has developed, work has become possible in a variety of locations and working from home has become more active. Intranet-type information network access was physically connected within the corporate building. Currently, access to the Internet is possible from outside, regardless of geographical location. Because of this, in addition to strengthening internal security, numerous studies are being conducted on external threat factors, user authentication, and data security. However, sophisticated attacks require security technologies such as enhanced network access control and strict user authentication. In this study, we propose an Abnormal Behavior Detection Mechanism (ABDM) that analyzes packets for various purposes for external access and determines abnormal behavior using a zero-trust perspective. ABDM approached users, systems, and time series to analyze packets and determine abnormal behavior. As a result, an accuracy of approximately 93% for abnormal behavior was measured.</p>","PeriodicalId":14138,"journal":{"name":"International Journal of Information Technology","volume":"3 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2024-08-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Abnormal behavior detection mechanism using deep learning for zero-trust security infrastructure\",\"authors\":\"Hyun-Woo Kim, Eun-Ha Song\",\"doi\":\"10.1007/s41870-024-02110-7\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p>As ICT technology has developed, work has become possible in a variety of locations and working from home has become more active. Intranet-type information network access was physically connected within the corporate building. Currently, access to the Internet is possible from outside, regardless of geographical location. Because of this, in addition to strengthening internal security, numerous studies are being conducted on external threat factors, user authentication, and data security. However, sophisticated attacks require security technologies such as enhanced network access control and strict user authentication. In this study, we propose an Abnormal Behavior Detection Mechanism (ABDM) that analyzes packets for various purposes for external access and determines abnormal behavior using a zero-trust perspective. ABDM approached users, systems, and time series to analyze packets and determine abnormal behavior. As a result, an accuracy of approximately 93% for abnormal behavior was measured.</p>\",\"PeriodicalId\":14138,\"journal\":{\"name\":\"International Journal of Information Technology\",\"volume\":\"3 1\",\"pages\":\"\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2024-08-28\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"International Journal of Information Technology\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1007/s41870-024-02110-7\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Information Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1007/s41870-024-02110-7","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

随着信息和通信技术的发展,在不同地点工作成为可能,在家工作也变得更加活跃。内联网类型的信息网络访问是在公司大楼内实际连接的。目前,无论地理位置如何,都可以从外部接入互联网。因此,除了加强内部安全外,还对外部威胁因素、用户身份验证和数据安全进行了大量研究。然而,复杂的攻击需要安全技术,如加强网络访问控制和严格的用户身份验证。在本研究中,我们提出了一种异常行为检测机制(ABDM),它能分析各种目的的外部访问数据包,并从零信任的角度确定异常行为。ABDM 采用用户、系统和时间序列来分析数据包并确定异常行为。结果,测得异常行为的准确率约为 93%。
本文章由计算机程序翻译,如有差异,请以英文原文为准。

Abnormal behavior detection mechanism using deep learning for zero-trust security infrastructure

Abnormal behavior detection mechanism using deep learning for zero-trust security infrastructure

As ICT technology has developed, work has become possible in a variety of locations and working from home has become more active. Intranet-type information network access was physically connected within the corporate building. Currently, access to the Internet is possible from outside, regardless of geographical location. Because of this, in addition to strengthening internal security, numerous studies are being conducted on external threat factors, user authentication, and data security. However, sophisticated attacks require security technologies such as enhanced network access control and strict user authentication. In this study, we propose an Abnormal Behavior Detection Mechanism (ABDM) that analyzes packets for various purposes for external access and determines abnormal behavior using a zero-trust perspective. ABDM approached users, systems, and time series to analyze packets and determine abnormal behavior. As a result, an accuracy of approximately 93% for abnormal behavior was measured.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信