Letter to Editor
BibTex RIS Cite

A User and Entity Behavior Analysis for SIEM Systems: Preprocessing of The Computer Emergency and Response Team Dataset

Year 2023, Volume: 4 Issue: 1, 1 - 6, 25.06.2023
https://doi.org/10.55195/jscai.1213782

Abstract

A lot of work has been done to prevent attacks from external sources and a great deal of success has been achieved. However, studies to detect internal attacks aren’t sufficient today. One of the most important studies for the detection of insider attacks is User and Entity Behavior Analysis (UEBA). In this letter, UEBA studies in the literature were reviewed and The Computer Emergency and Response Team Dataset was analyzed (CERT). For this purpose, preprocessing and feature extraction steps were applied on CERT datasets. Several log files combined with respect to user and for each user the number of activities in the specified time interval were obtained. The python code of these preprocessing and feature extraction steps were shared as open source in GitHub platform. In the final phase, future analysis was described and UEBA system planned to be designed was explained.

Supporting Institution

Detaysoft

Thanks

This study is an output of studies conducted in Detaysoft research and development center. We appreciate their support

Year 2023, Volume: 4 Issue: 1, 1 - 6, 25.06.2023
https://doi.org/10.55195/jscai.1213782

Abstract

There are 0 citations in total.

Details

Primary Language English
Subjects Artificial Intelligence, Computer Software
Journal Section Research Articles
Authors

Yasin Görmez 0000-0001-8276-2030

Halil Arslan 0000-0003-3286-5159

Yunus Emre Işık 0000-0001-6176-7545

İbrahim Ethem Dadaş 0000-0003-3745-7015

Early Pub Date June 30, 2023
Publication Date June 25, 2023
Submission Date December 2, 2022
Published in Issue Year 2023 Volume: 4 Issue: 1

Cite

APA Görmez, Y., Arslan, H., Işık, Y. E., Dadaş, İ. E. (2023). A User and Entity Behavior Analysis for SIEM Systems: Preprocessing of The Computer Emergency and Response Team Dataset. Journal of Soft Computing and Artificial Intelligence, 4(1), 1-6. https://doi.org/10.55195/jscai.1213782
AMA Görmez Y, Arslan H, Işık YE, Dadaş İE. A User and Entity Behavior Analysis for SIEM Systems: Preprocessing of The Computer Emergency and Response Team Dataset. JSCAI. June 2023;4(1):1-6. doi:10.55195/jscai.1213782
Chicago Görmez, Yasin, Halil Arslan, Yunus Emre Işık, and İbrahim Ethem Dadaş. “A User and Entity Behavior Analysis for SIEM Systems: Preprocessing of The Computer Emergency and Response Team Dataset”. Journal of Soft Computing and Artificial Intelligence 4, no. 1 (June 2023): 1-6. https://doi.org/10.55195/jscai.1213782.
EndNote Görmez Y, Arslan H, Işık YE, Dadaş İE (June 1, 2023) A User and Entity Behavior Analysis for SIEM Systems: Preprocessing of The Computer Emergency and Response Team Dataset. Journal of Soft Computing and Artificial Intelligence 4 1 1–6.
IEEE Y. Görmez, H. Arslan, Y. E. Işık, and İ. E. Dadaş, “A User and Entity Behavior Analysis for SIEM Systems: Preprocessing of The Computer Emergency and Response Team Dataset”, JSCAI, vol. 4, no. 1, pp. 1–6, 2023, doi: 10.55195/jscai.1213782.
ISNAD Görmez, Yasin et al. “A User and Entity Behavior Analysis for SIEM Systems: Preprocessing of The Computer Emergency and Response Team Dataset”. Journal of Soft Computing and Artificial Intelligence 4/1 (June 2023), 1-6. https://doi.org/10.55195/jscai.1213782.
JAMA Görmez Y, Arslan H, Işık YE, Dadaş İE. A User and Entity Behavior Analysis for SIEM Systems: Preprocessing of The Computer Emergency and Response Team Dataset. JSCAI. 2023;4:1–6.
MLA Görmez, Yasin et al. “A User and Entity Behavior Analysis for SIEM Systems: Preprocessing of The Computer Emergency and Response Team Dataset”. Journal of Soft Computing and Artificial Intelligence, vol. 4, no. 1, 2023, pp. 1-6, doi:10.55195/jscai.1213782.
Vancouver Görmez Y, Arslan H, Işık YE, Dadaş İE. A User and Entity Behavior Analysis for SIEM Systems: Preprocessing of The Computer Emergency and Response Team Dataset. JSCAI. 2023;4(1):1-6.