AUBIT: An Adaptive User Behaviour Based Insider Threat Detection Technique Using LSTM-Autoencoder
Ambairam Muthu Sivakrishna, R. Mohan, Krunal Dhanraj Randive · 2023
The most destructive cyber-attacks are often carried out by trustworthy insiders rather than suspicious outsiders or advanced persistent threats. Insiders significantly impact external factors by circumventing procedures and hiding in plain sight, leading to a substantial loss of organizational resources. Moreover, the existing approaches detect insiders with higher false alarm rates, creating chaos within an organization and demoralizing the organization’s routine. This research focuses on detecting insider threats on Carnegie Mellon University’s CERT version 4.2 synthetic dataset by analyzing user behavior based on their activities. AUBIT, an Autoencoders-based Long Short-Term Memory (LSTM) approach, is presented to identify insiders with improved efficacy and lower false alarm rates. When compared to other baseline methods, the proposed method has competitive results with an accuracy of (93.63%) , precision (97.19%), false alarm rate (2.5%), and F1 score (96%).