AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
PDF (5.7 MB)
Collect
Submit Manuscript AI Chat Paper
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Research Article | Open Access

Cybersecurity threat detection based on a UEBA framework using Deep Autoencoders

Jose Fuentes1Ines Ortega-Fernandez1( )Nora M. Villanueva2,3Marta Sestelo2,3
Galician Research and Development Center in Advanced Telecommunications (Gradiant), 36214 Vigo, Spain
Galician Center for Mathematical Research and Technology (CITMAga), 15782 Santiago de Compostela, Spain
Universidade de Vigo, Department of Statistics and O.R. & SiDOR Group, 36310 Vigo, Spain
Show Author Information

Abstract

The increasing sophistication of cyberattacks, especially insider and process-related anomalies, poses a major challenge to enterprises, as traditional rule-based or shallow anomaly detection systems often fail to capture complex behavioral patterns. User and Entity Behavior Analytics (UEBA) is a broad branch of data analytics that attempts to build a normal behavioral profile in order to detect anomalous events. Among the techniques used to detect anomalies, deep autoencoders constituted one of the most promising deep learning models on UEBA tasks, allowing explainable detection of security incidents that could lead to the leak of personal data, hijacking of systems, or access to sensitive business information. In this study, we introduced the first implementation of an explainable UEBA-based anomaly detection framework that leveraged deep autoencoders in combination with Doc2Vec, a neural network-based approach that learns the distributed representation of documents, to process both numerical and textual features. Additionally, based on the theoretical foundations of neural networks, we offered a novel proof demonstrating the equivalence of two widely used definitions for fully-connected neural networks. The experimental results demonstrated the proposed framework's capability to detect real and synthetic anomalies effectively generated from real attack data, showing that the models provided not only correct identification of anomalies but also explainable results that enabled the reconstruction of the possible origin of the anomaly. Compared to existing UEBA and anomaly detection approaches, the novelty of our framework lied in combining explainable multimodal feature processing with formal mathematical guarantees. Our findings suggested that the proposed UEBA framework can be seamlessly integrated into enterprise environments.

CLC number: 68M25, 68T07

References

【1】
【1】
 
 
AIMS Mathematics
Pages 23496-23517

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Fuentes J, Ortega-Fernandez I, Villanueva NM, et al. Cybersecurity threat detection based on a UEBA framework using Deep Autoencoders. AIMS Mathematics, 2025, 10(10): 23496-23517. https://doi.org/10.3934/math.20251043

135

Views

3

Downloads

1

Crossref

0

Web of Science

0

Scopus

Received: 29 March 2025
Revised: 26 September 2025
Accepted: 30 September 2025
Published: 16 October 2025
©2025 the Author(s), licensee AIMS Press.

This is an open access article distributed under the terms of the Creative Commons Attribution License (https://creativecommons.org/licenses/by/4.0)