A Novel Hybrid Model Merging LOF and iForest Algorithms for Insider Threats Detection

Anvita Mahajan · 2024

Insider threats are among the most difficult challenges in cybersecurity, often leading to substantial losses for organizations. Insider threats remain a well-researched area of cybersecurity, with continuous development of detection techniques to combat this persistent challenge. This research investigates the effectiveness of various anomaly detection algorithms, specifically focusing on the Locality Outlier Factor (LOF) and Isolation Forest (IF) algorithms. The study conducts a comprehensive comparative analysis to evaluate their performance in identifying anomalous data points. By delving into the strengths and weaknesses of each approach, the research aims to provide valuable insights into choosing the most suitable algorithm for different anomaly detection applications. This paper goes beyond individual anomaly detection algorithms by proposing a novel hybrid model that leverages the strengths of both Locality Outlier Factor (LOF) and Isolation Forest (IF). This innovative approach demonstrably outperforms both standalone methods in detecting insider threats, achieving a remarkable accuracy of 99%.

Read the paper · More papers on PaperTik