상세 보기
비지도 학습 기반 내부자 위협 탐지:Windows 아티팩트 중심 분석
- 이지민;
- 장항배
초록
Insider threats refer to actions in which an internal member of an organization abuses legitimate access privileges to leak data or compromise systems. Such threats have increasingly become a major factor in recent security incidents across corporations and public institutions. Traditional rule-based security systems have limitations in detecting stealthy insider behaviors that mimic normal activities. To address this, unsupervised anomaly detection techniques are gaining attention. In this study, user activity logs were collected and refined based on Windows artifacts such as Prefetch, Jumplist, and Event Logs. Features were structured in time-aligned units and applied to unsupervised learning models. The main detection models included One-Class SVM, Isolation Forest, Local Outlier Factor, and Gaussian Mixture Model, and a majority-voting-based ensemble method was also applied. In particular, this study further analyzed the detected anomalous behaviors to identify indications with a high likelihood of data exfiltration. Analysis results showed that GMM and One-Class SVM achieved high F1-scores, indicating strong performance in detecting insider threats, while the ensemble model also demonstrated stable detection capabilities. This study presents the potential for effectively identifying insider threats in real-world environments by integrating diverse log data and applying unsupervised anomaly detection techniques.
키워드
- 제목
- 비지도 학습 기반 내부자 위협 탐지:Windows 아티팩트 중심 분석
- 제목 (타언어)
- Insider Threat Detection Based on Unsupervised Learning: Focused Analysis on Windows Artifacts
- 저자
- 이지민; 장항배
- 발행일
- 2025-08
- 유형
- Y
- 저널명
- 한국전자거래학회지
- 권
- 30
- 호
- 3
- 페이지
- 21 ~ 36