Powered by OpenAIRE graph
Found an issue? Give us feedback
ZENODOarrow_drop_down
ZENODO
Article . 2024
License: CC BY
Data sources: Datacite
ZENODO
Article . 2024
License: CC BY
Data sources: Datacite
versions View all 2 versions
addClaim

Behavioral Analytics Using Machine Learning For Insider Threat Detection

Authors: Deepak Tomar; Kismat Chhillar;

Behavioral Analytics Using Machine Learning For Insider Threat Detection

Abstract

Insider threats remain one of the most complex and costly cybersecurity challenges faced by modern organizations, as malicious or negligent actions originate from trusted users who possess legitimate access to critical systems and sensitive information. Traditional rule-based detection mechanisms often fail to identify subtle behavioral deviations that precede insider incidents, resulting in delayed response and elevated organizational risk. This study proposes a behavioral analytics framework powered by machine learning techniques to detect insider threats through dynamic modeling of user activity patterns. By leveraging multi-source organizational logs, including authentication records, file access events, communication metadata, and network activity traces, the framework constructs individualized behavioral baselines and identifies anomalous deviations indicative of potential threat activity. Both supervised and unsupervised learning models are evaluated using a benchmark insider threat dataset, with careful attention to data imbalance mitigation and model interpretability. Experimental results demonstrate that ensemble learning methods and temporal modeling approaches significantly enhance detection accuracy while maintaining acceptable false positive rates. The findings underscore the importance of integrating behavioral machine learning models into Security Operations Centers to enable proactive, scalable, and context-aware insider threat mitigation strategies.

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
0
Average
Average
Average
Upload OA version
Are you the author of this publication? Upload your Open Access version to Zenodo!
It’s fast and easy, just two clicks!