A Detection Method for the Resource Misuses in Information Systems

作者:Wang Chao*; Zhang Gaoyu; Liu Lan
来源:International Conference on Affective Computing and Intelligent Interaction (ICACH 2012), 2012-02-27 to 2012-02-28.

摘要

It is difficult to detect the resource misuses in information systems because they can be carried out in different manners and it is hard to collect the prior knowledge of the malicious insiders. In this paper, a hidden Markov model (HMM) based method is developed to detect the resource misuse. As to the HMM model, the file folders containing sensitive information are taken as the model states and the user operations as the model observation symbols and Baum-Welch algorithm is adopted to determine the model parameters. The behavior profile of a malicious insider is depicted by his HMM model and used to detect his malicious behaviors. The experiment results show the effectiveness and adaptability of our method.