Preventing Data Breaches: Utilizing Log Analysis and Machine Learning for Insider Attack Detection
Haydar Teymourlouei, Vareva E. Harris · 2022
Insider attacks are rapidly growing and expanding in complexity. As a result, security measures must be able to strengthen intrusion detection and prevention. These challenges are intensified as data becomes unbalanced, behavior is irregular, and ground truth is limited. We propose a machine learning approach that uses random forest to predict insider attacks. Network activity is collected from servers to analyze user behavior and make predictions about future insider attacks. The goal of this method is to prevent future data breaches by making accurate predictions. The results show that a machine-learning based system with the random forest classifier is accurate with high-quality training data. The methodology shows 99% accuracy. Feature selection identified several feature subsets that were redundant.