Integration of recommender systems into UEBA architecture for behavioral anomaly detection
The work is devoted to the problem of detecting behavioral anomalies in corporate information systems that are potentially related to the actions of internal intruders. During the work, an analysis of existing UEBA (User and Entity Behavior Analytics) systems was conducted. The identified shortcomings of known solutions highlight the need to create new approaches to analyzing user behavior. As a solution, an approach to integrating recommendation systems into the UEBA architecture was developed, based on rephrasing the task of anomaly detection as a task of estimating the typicality of user behavior based on collective experience. The feasibility of this approach was theoretically justified and experimentally confirmed. The obtained results demonstrate the superiority of the proposed approach over the basic methods in terms of Precision and F1-score metrics and can be used to create new protective solutions.


