Enhancing Security Service of Data Protection Level using Machine Learning

P. Velmurugadass, S. Dhanasekaran · 2021 2nd Global Conference for Advancement in Technology (GCAT) · 2021

Insider threats become more dangerous and introduce high risk in the organization. In general, insider attackers seek to theft or alter the organization data with intentions. As insider threats are more difficult to detect, still major issues are there. In this research, the machine learning (ML) approach is proposed to analyze and detect insider threats. This project focuses on detecting insiders by learning the behaviour of insider threats continuously. At first, the insider dataset is collected and pre-processed. The preprocessing step breaks the data into a granular level (i.e.) weekly, daily and hourly behaviour data. Then, this data is processed with feature extraction in which the required features including HTTP features, E-mail features, file features, and USB features are extracted from each data instance. These are the main feature categories and each category consists of several features that are useful in insider detection. Then, the features are fed into the Random Forest (RF) classifier, one of the best ML algorithms. Finally, the RF classifies data into insiders and normally based on the features. The experimental analysis shows that the proposed ML-based insider threat detection model in granular level works is more accurate.

Read the paper · More papers on PaperTik