Employee Watcher: A Machine Learning-based Hybrid Insider Threat Detection Framework

Usman Rauf, Zhiyuan Wei, Fadi Mohsen · 2023

Insider threats refer to harmful actions carried out by authorized users within an organization, posing the most damaging risks. The increasing number of these threats has revealed the inadequacy of traditional methods for detecting and mitigating insider threats. These existing approaches lack the ability to analyze activity-related information in detail, resulting in delayed detection of malicious intent. To address this, our paper presents a hybrid insider threat detection framework. We enhance prediction accuracy by incorporating a layer of statistical criteria using information gain metrics on top of Machine Learning-based classification. We evaluate the performance of our framework using a real-life threat test dataset (CERT r4.2) and compare it to existing methods on the same dataset [7]. Our initial evaluation demonstrates that our proposed framework achieves an accuracy of 98.94% in detecting insider threats, surpassing the performance of existing methods. Additionally, our framework effectively handles potential bias and data imbalance issues that can arise in real-life scenarios.

Read the paper · More papers on PaperTik