用五维信任模型检测账号劫持,解释性强且效果显著。
Multi-Axis Trust Modeling for Interpretable Account Hijacking Detection
- 构建五维信任模型,融合长期信誉、行为精度等26个特征。
- 在CLUE-LDS数据集上,随机森林检测准确率接近完美。
- 时间特征提升检测效果,适合高风险场景的可信检测。
本文提出一种受伊斯兰圣训学启发的多轴信任建模框架,将长期完整性(adalah)、行为精确性(dabt)、上下文连续性(isnad)、累计声誉和异常证据五维信任指标转化为26个语义明确的用户行为特征,并引入轻量级时间特征捕捉连续活动窗口中的信任信号变化。在注入劫持场景的CLUE-LDS云活动数据集上,基于信任特征训练的随机森林模型在23,094个滑动窗口中实现近乎完美的检测性能,显著优于基于原始事件计数、最小统计基线和无监督异常检测的模型。时间特征在CLUE-LDS上带来稳定但有限的提升。为评估鲁棒性,进一步在极端类别不平衡且恶意行为稀疏的CERT Insider Threat Test Dataset r6.2上测试:在500人子集上,时间特征使ROC-AUC从0.776提升至0.844;在4,000人泄漏控制配置下,静态信任特征基础上加入时间建模使ROC-AUC从0.627升至0.715,PR-AUC从0.072增至0.264,效果显著且一致。
原文摘要 · Abstract (English)
This paper proposes a Hadith-inspired multi-axis trust modeling framework, motivated by a structurally analogous problem in classical Hadith scholarship: assessing the trustworthiness of information sources using interpretable, multidimensional criteria rather than a single anomaly score. We translate five trust axes - long-term integrity (adalah), behavioral precision (dabt), contextual continuity (isnad), cumulative reputation, and anomaly evidence - into a compact set of 26 semantically meaningful behavioral features for user accounts. In addition, we introduce lightweight temporal features that capture short-horizon changes in these trust signals across consecutive activity windows. We evaluate the framework on the CLUE-LDS cloud activity dataset with injected account hijacking scenarios. On 23,094 sliding windows, a Random Forest trained on the trust features achieves near-perfect detection performance, substantially outperforming models based on raw event counts, minimal statistical baselines, and unsupervised anomaly detection. Temporal features provide modest but consistent gains on CLUE-LDS, confirming their compatibility with the static trust representation. To assess robustness under more challenging conditions, we further evaluate the approach on the CERT Insider Threat Test Dataset r6.2, which exhibits extreme class imbalance and sparse malicious behavior. On a 500-user CERT subset, temporal features improve ROC-AUC from 0.776 to 0.844. On a leakage-controlled 4,000-user configuration, temporal modeling yields a substantial and consistent improvement over static trust features alone (ROC-AUC 0.627 to 0.715; PR-AUC 0.072 to 0.264).
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。