Thee Machine Learning Analysis of Data Granularity for Insider Threat Detection
Rakesh Kumar · 2023
There is a growing and serious risk to the company from insider threats. In most cases, malicious insiders target sensitive company information for theft or manipulation. There are still substantial problems despite the fact that insider threats are harder to identify. The goal of this research is to assess and identify insider threats using a machine learning (ML) technique. The goal of this research is to identify potential insider threats by continuous learning of their behaviors. The initial step is to gather and prepare the insider dataset. The data is first preprocessed to create smaller, more manageable chunks, such as weekly, daily, and hourly behavioural data. The next step is feature extraction, whereby the necessary features are culled from each data instance; this includes but is not limited to HTTP features, E-mail capabilities, file features, and USB characteristics. These are the primary types of characteristics, and insider detection may make use of features from across each of them. Next, one of the most effective ML algorithms, Random Forest (RF) classifier, is given the characteristics. At last, the RF sorts information into “insider“ and “normal“ categories according to the characteristics. The experimental results demonstrate the efficacy of the proposed ML-based identifying insider threats model at the microlevel.