An approach to detect user behaviour anomalies within identity federations
dc.contributor.author | Martín, Alejandro G. | |
dc.contributor.author | Beltrán, Marta | |
dc.contributor.author | Fernández-Isabel, Alberto | |
dc.contributor.author | Martín de Diego, Isaac | |
dc.date.accessioned | 2022-02-09T12:16:23Z | |
dc.date.available | 2022-02-09T12:16:23Z | |
dc.date.issued | 2021 | |
dc.description.abstract | User and Entity Behaviour Analytics (UEBA) mechanisms rely on statistical techniques and Machine Learning to determine when a significant deviation from patterns or trends established as a standard for users and entities is occurring. These mechanisms are beneficial within cybersecurity contexts because they allow managers and administrators to have early alerts warning about potential security incidents. This paper proposes the utilisation of UEBA to improve the security of Federated Identity Management (FIM) solutions. The proposed UEBA workflow allows Relying Parties within identity federations to build a session fingerprint characterising each user’s behaviour from available information. Furthermore, it enables anomaly detection based on this fingerprint, integrating raised alerts within current identity management specifications. The proposed workflow is validated and evaluated in a real use case based on a web chat application using OpenID Connect for identity management. | es |
dc.description.sponsorship | S0167404821001802 | es |
dc.identifier.citation | Alejandro G. Martín, Marta Beltrán, Alberto Fernández-Isabel, Isaac Martín de Diego, An approach to detect user behaviour anomalies within identity federations, Computers & Security, Volume 108, 2021, 102356, ISSN 0167-4048, https://doi.org/10.1016/j.cose.2021.102356 | es |
dc.identifier.doi | 10.1016/j.cose.2021.102356 | es |
dc.identifier.issn | 0167-4048 | |
dc.identifier.uri | http://hdl.handle.net/10115/18638 | |
dc.language.iso | eng | es |
dc.publisher | Elsevier | es |
dc.rights | Attribution-NonCommercial-NoDerivatives 4.0 Internacional | * |
dc.rights.accessRights | info:eu-repo/semantics/openAccess | es |
dc.rights.uri | http://creativecommons.org/licenses/by-nc-nd/4.0/ | * |
dc.subject | Anomaly detection | es |
dc.subject | Behavioural fingerprint | es |
dc.subject | Federated identity management | es |
dc.subject | Machine learning | es |
dc.subject | User and entity behaviour analytics | es |
dc.title | An approach to detect user behaviour anomalies within identity federations | es |
dc.type | info:eu-repo/semantics/article | es |
Archivos
Bloque original
1 - 1 de 1
Cargando...
- Nombre:
- 1-s2.0-S0167404821001802-main.pdf
- Tamaño:
- 1.66 MB
- Formato:
- Adobe Portable Document Format
- Descripción: