비지도 학습 기반 내부자 위협 탐지:Windows 아티팩트 중심 분석

Insider Threat Detection Based on Unsupervised Learning: Focused Analysis on Windows Artifacts

초록

Insider threats refer to actions in which an internal member of an organization abuses legitimate access privileges to leak data or compromise systems. Such threats have increasingly become a major factor in recent security incidents across corporations and public institutions. Traditional rule-based security systems have limitations in detecting stealthy insider behaviors that mimic normal activities. To address this, unsupervised anomaly detection techniques are gaining attention. In this study, user activity logs were collected and refined based on Windows artifacts such as Prefetch, Jumplist, and Event Logs. Features were structured in time-aligned units and applied to unsupervised learning models. The main detection models included One-Class SVM, Isolation Forest, Local Outlier Factor, and Gaussian Mixture Model, and a majority-voting-based ensemble method was also applied. In particular, this study further analyzed the detected anomalous behaviors to identify indications with a high likelihood of data exfiltration. Analysis results showed that GMM and One-Class SVM achieved high F1-scores, indicating strong performance in detecting insider threats, while the ensemble model also demonstrated stable detection capabilities. This study presents the potential for effectively identifying insider threats in real-world environments by integrating diverse log data and applying unsupervised anomaly detection techniques.

키워드

내부자 위협비지도 학습이상행위 탐지유출 징후 탐지디지털 아티팩트앙상블 기법Insider ThreatUnsupervised LearningAnomaly DetectionDetection of spill signsDigital ArtifactEnsemble Techniques
제목
비지도 학습 기반 내부자 위협 탐지:Windows 아티팩트 중심 분석
제목 (타언어)
Insider Threat Detection Based on Unsupervised Learning: Focused Analysis on Windows Artifacts
저자
이지민장항배
DOI
10.7838/jsebs.2025.30.3.021
발행일
2025-08
유형
Y
저널명
한국전자거래학회지
30
3
페이지
21 ~ 36