2012 IEEE Symposium on Security and Privacy Workshops (2013)
San Francisco, CA, USA USA
May 23, 2013 to May 24, 2013
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/SPW.2013.38
Authentication using centralized methods is aprimary trust mechanism within most large-scale, enterprisecomputer networks. This paper proposes using graphs torepresent user authentication activity within the network. Usingthis mechanism over a real enterprise network dataset, we findthat non-privileged users and users with system administrationprivileges have distinguishable graph attributes in terms of sizeand complexity. In addition, we find that user authenticationgraphs provide intuitive insights into network user behavior.We believe that understanding these differences in even greaterdetail will lead to improved user behavior profiling and theelusive detection of authentication credential misuse.
Alexander D. Kent, Lorie M. Liebrock, "Differentiating User Authentication Graphs", 2012 IEEE Symposium on Security and Privacy Workshops, vol. 00, no. , pp. 72-75, 2013, doi:10.1109/SPW.2013.38