3 papers
cs.CR2025
Democratizing ML for Enterprise Security: A Self-Sustained Attack Detection Framework
Sadegh Momeni, Ge Zhang, Birkett Huber +4
Despite advancements in machine learning for security, rule-based detection remains prevalent in Security Operations Centers due to the resource intensiveness and skill gap associa…
cs.CR2024
Facade: High-Precision Insider Threat Detection Using Deep Contextual Anomaly Detection
Alex Kantchelian, Casper Neo, Ryan Stevens +10
Insiders with privileged access have the power to cause great harm to their organization. Even a single insider threat incident can be catastrophic, resulting in both financial los…
cs.CR2024
Fine Grained Insider Risk Detection
Birkett Huber, Casper Neo, Keiran Sampson +3
We present a method to detect departures from business-justified workflows among support agents. Our goal is to assist auditors in identifying agent actions that cannot be explaine…