用贝叶斯框架检测企业目录访问中的恶意行为
A Consensus-Bayesian Framework for Detecting Malicious Activity in Enterprise Directory Access Graphs
- 基于多层交互图建模用户与目录的动态关系
- 通过意见方差突变发现违反结构规范的异常行为
- 支持在线更新,适合持续监控企业安全
本文提出一种基于共识的贝叶斯框架,用于检测企业目录访问图中的恶意用户行为。将目录建模为话题,用户作为多层级交互图中的主体,利用加权影响的意见动态模拟访问演化过程。用户间的逻辑依赖由动态矩阵 Ci 编码,目录相似性通过共享影响矩阵 W 捕捉。恶意行为以跨组件逻辑扰动形式注入,破坏强连通分量(SCCs)的结构规范。结合意见动态理论,确定话题收敛性,并通过缩放意见方差检测异常。引入贝叶斯异常评分机制,结合静态与在线先验,实现不确定性量化。在合成访问图上的仿真验证了方法对逻辑不一致的敏感性及在动态扰动下的鲁棒性。
原文摘要 · Abstract (English)
This work presents a consensus-based Bayesian framework to detect malicious user behavior in enterprise directory access graphs. By modeling directories as topics and users as agents within a multi-level interaction graph, we simulate access evolution using influence-weighted opinion dynamics. Logical dependencies between users are encoded in dynamic matrices Ci, and directory similarity is captured via a shared influence matrix W. Malicious behavior is injected as cross-component logical perturbations that violate structural norms of strongly connected components(SCCs). We apply theoretical guarantees from opinion dynamics literature to determine topic convergence and detect anomaly via scaled opinion variance. To quantify uncertainty, we introduce a Bayesian anomaly scoring mechanism that evolves over time, using both static and online priors. Simulations over synthetic access graphs validate our method, demonstrating its sensitivity to logical inconsistencies and robustness under dynamic perturbation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。