A Pragmatic Enquiry to Learn Recent Trends in Insider Threat Detection Approaches

G Sandra, Salaja Silas, Elijah Blessing Rajsingh · 2024

Insider threat has become a recurring and serious challenge faced by organization throughout the world. It shows an increasing trend from 2003 onwards. Due to the widespread use of internet, the hackers and intruders crept into network system and its trend also increased continuously. To resist the issues of insider threat, enterprises adopted and implemented many intrusion detection and prevention mechanisms, which can be classified as traditional and modern security solutions. The insiders have legitimate access to the vital information system of an organization. It is noted that not all the insiders are threat to an enterprise. Only a minority group, who for the materialization of their personal gains, misuse their given administrative rights to access the sensitive resources of an enterprise. They either evade or hide themselves from being caught for their malevolent deeds by utilizing their legitimate access rights. Hence, their malicious activities go undetected, which cause greater damages to every organization and thus the prevailing threat detection and prevention mechanisms remain ineffective. Another reason for inefficacy of the various threat detection and prevention approaches is the lack of hand-to-hand awareness about the factors governing the formulation of threat detection and prevention approaches. Hence, this review presents an account of these factors in recent threat detection literature, by giving an overview of insider threat events, actors, insider threat detection techniques, datasets used for training and testing, feature domains, and performance metrics used to measure the accuracy of the models proposed. This study also envisages that our review on the insider threat will help the researchers in this field to get more clarity about the factors to be considered to frame effective threat detection mechanisms.

Read the paper · More papers on PaperTik