Методы анализа поведения пользователей в информационных системах
Журнал: НБИ технологии @nbi-technologies
Рубрика: Информационные технологии в безопасности и телекоммуникациях
Статья в выпуске: 1 т.19, 2025 года.
Бесплатный доступ
Проанализирована статистика угроз поведения пользователей в информационных системах. Определена процедура анализа поведения пользователей в информационной системе. Представлена классификация методов анализа поведения пользователей в информационных системах. Для выявления наиболее эффективного метода анализа поведения пользователей в информационных системах определены критерии для их сравнения. Приведен результат сравнения методов анализа поведения пользователей в информационной системе по выделенным критериям.
Короткий адрес: https://sciup.org/149151782
IDS: 149151782 | УДК: 004.775 | DOI: 10.15688/NBIT.jvolsu.2025.1.1
Methods for analyzing user behavior in information systems
This article examines methods for analyzing user behavior in information systems, focusing on identifying anomalies and preventing security threats. The authors highlight the growing risk of cyberattacks, emphasizing that 79% of data breaches result from human actions, whether intentional or accidental. Traditional security measures like firewalls and antivirus software are insufficient, necessitating advanced behavioral analysis to detect unusual activities early. The study presents a classification of methods for analyzing user behavior, including anomaly detection, event sequence analysis, classification techniques, network interaction analysis, text analysis, and neural network-based approaches. Each method is evaluated based on criteria such as accuracy, implementation complexity, adaptability, training time, and comprehensiveness. The Euclidean distance metric is applied to compare these methods, revealing that event sequence analysis is the most effective for identifying deviations in user behavior. The findings underscore the importance of integrating multiple analytical approaches to enhance security systems. By combining methods like statistical analysis, machine learning, and graph algorithms, organizations can better detect both simple anomalies and complex threats. The article provides valuable insights for improving information security strategies, advocating for a proactive approach to mitigate risks posed by internal and external threats.