用AI动态评分和大模型检测内鬼,误报降59%、查出率升30%
AI-Driven IRM: Transforming insider risk management with adaptive scoring and LLM-based threat detection
- 用自编码器学习用户行为,动态生成风险评分取代旧模型
- 误报减少59%,真实威胁检出率提升30%,日处理千万级日志
- 适合需要自动响应的大型企业,尤其关注安全合规与效率
内部威胁对组织安全构成重大挑战,常因隐蔽性和上下文依赖性而逃过传统规则系统。本文提出一种AI驱动的内部风险管理系统(IRM),融合行为分析、动态风险评分与实时策略执行,实现高精度、强适应性的威胁检测与缓解。提出混合评分机制,由静态的PRISM模型演进为基于专家标注行为数据训练的自编码器神经网络模型。通过迭代反馈与持续学习,系统将误报率降低59%,真实威胁检出率提升30%,显著提升检测精度。平台可高效扩展,每日处理高达1000万条日志事件,查询延迟低于300ms,支持违规自动处置,减少人工干预。部署后事件响应时间缩短47%,凸显其实际效能。未来计划引入可解释AI、联邦学习、图式异常检测及零信任对齐,进一步增强适应性、透明度与合规能力。本研究建立了一套适用于本地与混合环境的可扩展、主动型内部风险防控框架。
原文摘要 · Abstract (English)
Insider threats pose a significant challenge to organizational security, often evading traditional rule-based detection systems due to their subtlety and contextual nature. This paper presents an AI-powered Insider Risk Management (IRM) system that integrates behavioral analytics, dynamic risk scoring, and real-time policy enforcement to detect and mitigate insider threats with high accuracy and adaptability. We introduce a hybrid scoring mechanism - transitioning from the static PRISM model to an adaptive AI-based model utilizing an autoencoder neural network trained on expert-annotated user activity data. Through iterative feedback loops and continuous learning, the system reduces false positives by 59% and improves true positive detection rates by 30%, demonstrating substantial gains in detection precision. Additionally, the platform scales efficiently, processing up to 10 million log events daily with sub-300ms query latency, and supports automated enforcement actions for policy violations, reducing manual intervention. The IRM system's deployment resulted in a 47% reduction in incident response times, highlighting its operational impact. Future enhancements include integrating explainable AI, federated learning, graph-based anomaly detection, and alignment with Zero Trust principles to further elevate its adaptability, transparency, and compliance-readiness. This work establishes a scalable and proactive framework for mitigating emerging insider risks in both on-premises and hybrid environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。