2021 IEEE International Conference on Big Data (Big Data) · 2021 · 10 citations · 38 references
Identifying suspicious user behavior within an enterprise network is vital to maintaining strong cyber security defenses. This paper presents a scalable approach to detecting anomalous user behavior in event logs, which we frame as a dynamic, bipartite interaction network of users and resources. Graph embedding is used to obtain vector representations of users, which are updated over time and used to model the profile of the users who typically access each resource. A standard nearest neighbor anomaly detection method is then employed to score new interactions. The approach is applied to a dataset of interaction events between users and SharePoint sites within Microsoft’s internal corporate network.
38
Statistical mechanics of complex networks
Réka Albert, Albert-Ĺaszló Barabási · Reviews of Modern Physics · 2002 · 20.2K citations · Full text
Indexing by latent semantic analysis
Scott Deerwester, Susan Dumais, George W. Furnas et al. · Journal of the American Society for Information Science · 1990 · 12.7K citations
Aditya Grover, Jure Leskovec · 2016 · 10.6K citations
2014 · 8.3K citations · Full text
Geometric Learning, Graph Neural Network, Network Science +14
On Spectral Clustering: Analysis and an algorithm
Andrew Y. Ng, Michael I. Jordan, Yair Weiss · 2001 · 7.8K citations