Deep Neural Networks for Detecting Insider Threats and Social Engineering Attacks
Marshet Tamirat Zewdie, Anteneh Girma, Tilahun Melak Sitote · 2024
Cybersecurity (CS) plays a crucial role in protecting valuable and sensitive organizational data, systems, computers, and networks from unauthorized access. However, the incressing prevalence of insider threats and social engineering attack (SEA) presents significant challenges in effectively detecting and mitigating of these risks. A yearly report from 2023 highlighted that despite 90% of companies implementing multiple security measures, they still experienced an average loss of $ 16 million per incident. The detection capabilities of existing detection methods, which are primarily network-based or host-based intrusion detection, have limitations. This article aims to enhance detection methods through a comprehensive analysis of network and host level insiders' behavior along with Deep Learning approaches. This proposed method of detection provide a unified and holistic detection. Insider threats, whether intentional or unintentional, also create vulnerabilities to external threats and attacks such as phishing and SEA attacks. By addressing the gap in insider threat detection, the proposed comprehensive analysis of insider network and host level activities will enhance detection performance and reduce security costs by compact the existing fragmented detection approaches. As a result the false positive and false negative alarms will reduce the cost of detection and mitigate business operation disturbances. Since insiders interact with network devices and computers as users, integrating their host and network behaviors' into the detection methods offer both enhanced detection capabilities and a unified detection. To evaluate the proposed detection method, an Auto-encoder Deep Learning model will be developed, and public network and host intrusion detesets will be utilized. Evaluation metrics such as Accuracy, precision, recall, and F1- score will be employed. Preliminary analysis results have shown the proposed compre-hensive behavior analysis with Deep Learning (DL) method promising outcomes for detecting insider threats and social engineering attacks (SEAs).