维普中文期刊产品整合服务

Detecting compromised email accounts via login behavior characterization

查看全文 作  者:Jianjun [1,2]Zhao;Can [1,2]Yang;Di [3]Wu;Yaqin [1,2]Cao;Yuling [1,2]Liu;Xiang [4]Cui;Qixu [1,2]Liu 高影响力作者 机构地区:[1]Institute of Information Engineering,Chinese Academy of Sciences,Beijing,100085,China;[2]School of Cyber Security,University of Chinese Academy of Sciences,Beijing,100049,China;[3]China Cybersecurity Review Technology and Certification Center,Beijing,100013,China;[4]Zhongguancun Laboratory,Beijing,100089,China高影响力机构 出  处:《Cybersecurity》索引2024年第7卷第1期,共21页高影响力期刊 基  金:supported by the Youth Innovation Promotion Association CAS(No.2019163);the Strategic Priority Research Program of Chinese Academy of Sciences(No.XDC02040100);the Key Laboratory of Network Assessment Technology at Chinese Academy of Sciences and Beijing Key Laboratory of Network security and Protection Technology. 摘  要:The illegal use of compromised email accounts by adversaries can have severe consequences for enterprises and society.Detecting compromised email accounts is more challenging than in the social network field,where email accounts have only a few interaction events(sending and receiving).To address the issue of insufficient features,we propose a novel approach to detecting compromised accounts by combining time zone differences and alternate logins to identify abnormal behavior.Based on this approach,we propose a compromised email account detection framework that relies on widely available and less sensitive login logs and does not require labels.Our framework characterizes login behaviors to identify logins that do not belong to the account owner and outputs a list of account-subnet pairs ranked by their likelihood of having abnormal login relationships.This approach reduces the number of account-subnet pairs that need to be investigated and provides a reference for investigation priority.Our evaluation demonstrates that our method can detect most email accounts that have been accessed by disclosed malicious IP addresses and outperforms similar research.Additionally,our framework has the capability to uncover undisclosed malicious IP addresses. 关 键 词:Compromised account detection Mixture model Login log analysis Attribution and forensic
相关文献

参考文献(27)

网站首页 | 关于我们 | 联系我们 | 产品服务 | 客服中心 | 广告服务 | 版权声明 | 网站联盟 | 友情链接 | 售卡网点

版权所有© 渝B2-20050021-1 渝公网安备 50019002500403号 违法和不良信息举报中心

互联网出版许可证 新出网证(渝)字10号 全国400电话 - 免长途话费