

信息通信技术与政策 ›› 2024, Vol. 50 ›› Issue (12): 73-81.doi: 10.12267/j.issn.2096-5931.2024.12.011

专题:人工智能赋能新型工业化 上一篇    下一篇


Design of data audit and security management system based on UEBA and AI

薛亮1, 汪含笑2, 胡晓波3, 韩海庭4   

  1. 1.中国移动通信集团江苏有限公司,南京 210029
    2.中国信息通信研究院安全研究所,北京 100191
    3.公安部第一研究所,北京 100010
    4.浙江海洋大学海天智能物联网实验室,舟山 316000
  • 收稿日期:2024-11-10 出版日期:2024-12-25 发布日期:2025-01-02
  • 通讯作者: 韩海庭
  • 作者简介:
    薛亮, 中国移动通信集团江苏有限公司工程师,长期从事通信网络安全、网络数据安全等方面的研究工作;
    汪含笑, 中国信息通信研究院安全研究所助理工程师,长期从事数据安全、网络安全相关方面的研究工作;
    胡晓波, 公安部第一研究所高级工程师,长期从事数据安全、数据治理、网络安全等方面的研究工作

XUE Liang1, WANG Hanxiao2, HU Xiaobo3, HAN Haiting4   

  1. 1. China Mobile Communications Group Jiangsu Co., Ltd., Nanjing 210029, China
    2. Security Research Institute, China Academy of Information and Communications Technology, Beijing 100191, China
    3. First Research Institute of the Ministry of Public Security, Beijing 100010, China
    4. Intelligent IoT Laboratory, Zhejiang Ocean University, Zhoushan 316000, China
  • Received:2024-11-10 Online:2024-12-25 Published:2025-01-02
  • Contact: HAN Haiting



关键词: 用户实体行为分析, 人工智能, 数据安全, 数据审计


A data auditing and security management system based on user and entity behavior analysis offers an innovative solution to address internal and external data security threats in enterprises. By continuously monitoring the behaviors of users, devices, and applications, the system establishes dynamic baselines and performs real-time anomaly detection to identify potential threats effectively. This paper proposes a framework centered on four key elements—entities, behaviors, baselines, and algorithms—along with a three-step process comprising data collection, behavior analysis, as well as response and handling. It demonstrates how artificial intelligence-enhanced user and entity behavior analysis (UEBA) can be used to construct an intelligent data security auditing system, strengthening data protection capabilities and ensuring compliance.

Key words: UEBA, artificial intelligence, data security, data audit
