Insider Threat Detection on CERT Data Using Pre-trained ResNet
Valaparla Rohini, R Mohan, Ambairam Muthu Sivakrishna · 2024
The detrimental cyber-attacks frequently originate from individuals or insiders within an organization who are considered reliable and trustworthy, as opposed to individuals with suspicious motives from outside the organization. This insider is difficult to detect, as it may not leave any evidence behind, yet possesses the potential to cause considerable harm to the organization. To tackle this issue, numerous researchers have diligently sought out various methods to effectively identify insider threats. These methods employed for the identification of insiders within an organization who pose a threat from within have been proven to yield elevated rates of false alarms, which in turn lead to a state of disarray and confusion within the organizational framework, consequently resulting in a dampening of morale among the members of the organization due to the disruption of their regular work. Therefore, a methodology was presented for categorizing insider threats that are motivated by the effectiveness of the classification of the images. The publicly available CERT r4.2 standard insider threat dataset was used and to avoid the class imbalance issue data augmentation was applied. The objective of this research is to detect insider threats and evaluate the ResNet50 model. Finally, the approach has achieved 97.54% accuracy and classified the insider threat efficiently.