• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

采用混合TCN变压器架构的每日内部威胁检测

Daily insider threat detection with hybrid TCN transformer architecture.

作者信息

Ye Xiaoyun, Cui Huangrongbin, Luo Faqin, Wang Jinlong, Xiong Xiaoyun, Zhang Wencui, Yu Jiawei, Zhao Wenhao

机构信息

School of Information and Control Engineering, Qingdao University of Technology, Qingdao, 266520, China.

School of Business, Qingdao Binhai University, Qingdao, 266555, China.

出版信息

Sci Rep. 2025 Aug 5;15(1):28590. doi: 10.1038/s41598-025-12063-x.

DOI:10.1038/s41598-025-12063-x
PMID:40764628
Abstract

Internal threats are becoming more common in today's cybersecurity landscape. This is mainly because internal personnel often have privileged access, which can be exploited for malicious purposes. Traditional detection methods frequently fail due to data imbalance and the difficulty of detecting hidden malicious activities, especially when attackers conceal their intentions over extended periods. Most existing internal threat detection systems are designed to identify malicious users after they have acted. They model the behavior of normal employees to spot anomalies. However, detection should shift from targeting users to focusing on discrete work sessions. Relying on post hoc identification is unacceptable for businesses and organizations, as it detects malicious users only after completing their activities and leaving. Detecting threats based on daily sessions has two main advantages: it enables timely intervention before damage escalates and captures context-relevant risk factors. Our research introduces a novel detection framework for single-day employee behavior detection to address these issues. This framework combines the strengths of Temporal Convolutional Networks (TCNs) and the Transformer architecture. The integrated model uses sliding window technology to segment user logs into time series for model input. The TCN component employs causal and dilated convolutions to maintain temporal order and expand the receptive field, enhancing the detection of long-term patterns. The Transformer models global dependencies in sequences, improving the detection of complex long-term behaviors. The model detects anomalies at each time step and achieves a recall rate of [Formula: see text] with a sequence length of 30 days. Experimental results show that this method can accurately detect malicious behavior daily, promptly identify such actions, and effectively mitigate internal threats in complex environments.

摘要

在当今的网络安全环境中,内部威胁正变得越来越普遍。这主要是因为内部人员通常具有特权访问权限,可能会被用于恶意目的。由于数据不平衡以及难以检测隐藏的恶意活动,传统的检测方法常常失效,尤其是当攻击者长时间隐藏其意图时。大多数现有的内部威胁检测系统旨在在恶意用户采取行动后进行识别。它们对正常员工的行为进行建模以发现异常。然而,检测应从针对用户转向关注离散的工作会话。对于企业和组织来说,依赖事后识别是不可接受的,因为它只能在恶意用户完成活动并离开后才检测到他们。基于日常会话检测威胁有两个主要优点:它能够在损害升级之前及时进行干预,并捕捉与上下文相关的风险因素。我们的研究引入了一种用于单日员工行为检测的新型检测框架来解决这些问题。该框架结合了时间卷积网络(TCN)和Transformer架构的优势。集成模型使用滑动窗口技术将用户日志分割成时间序列作为模型输入。TCN组件采用因果卷积和扩张卷积来保持时间顺序并扩大感受野,增强对长期模式的检测。Transformer对序列中的全局依赖关系进行建模,改进对复杂长期行为的检测。该模型在每个时间步检测异常,在序列长度为30天时召回率达到[公式:见原文]。实验结果表明,该方法能够每天准确检测恶意行为,及时识别此类行为,并在复杂环境中有效缓解内部威胁。

相似文献

1
Daily insider threat detection with hybrid TCN transformer architecture.采用混合TCN变压器架构的每日内部威胁检测
Sci Rep. 2025 Aug 5;15(1):28590. doi: 10.1038/s41598-025-12063-x.
2
Sexual Harassment and Prevention Training性骚扰与预防培训
3
The Black Book of Psychotropic Dosing and Monitoring.《精神药物剂量与监测黑皮书》
Psychopharmacol Bull. 2024 Jul 8;54(3):8-59.
4
Short-Term Memory Impairment短期记忆障碍
5
Management of urinary stones by experts in stone disease (ESD 2025).结石病专家对尿路结石的管理(2025年结石病专家共识)
Arch Ital Urol Androl. 2025 Jun 30;97(2):14085. doi: 10.4081/aiua.2025.14085.
6
Home treatment for mental health problems: a systematic review.心理健康问题的居家治疗:一项系统综述
Health Technol Assess. 2001;5(15):1-139. doi: 10.3310/hta5150.
7
How lived experiences of illness trajectories, burdens of treatment, and social inequalities shape service user and caregiver participation in health and social care: a theory-informed qualitative evidence synthesis.疾病轨迹的生活经历、治疗负担和社会不平等如何影响服务使用者和照顾者参与健康和社会护理:一项基于理论的定性证据综合分析
Health Soc Care Deliv Res. 2025 Jun;13(24):1-120. doi: 10.3310/HGTQ8159.
8
Identifying and Addressing Bullying识别与应对霸凌
9
Idiopathic (Genetic) Generalized Epilepsy特发性(遗传性)全身性癫痫
10
Automated monitoring compared to standard care for the early detection of sepsis in critically ill patients.与标准护理相比,自动监测用于危重症患者脓毒症的早期检测
Cochrane Database Syst Rev. 2018 Jun 25;6(6):CD012404. doi: 10.1002/14651858.CD012404.pub2.

本文引用的文献

1
A novel hybrid framework based on temporal convolution network and transformer for network traffic prediction.基于时间卷积网络和转换器的新型混合框架用于网络流量预测。
PLoS One. 2023 Sep 8;18(9):e0288935. doi: 10.1371/journal.pone.0288935. eCollection 2023.