Classifying Malicious Insider Threats Based On User Activity and Behavioral Profile Using Machine Learning

Fatima Rashed Alzaabi, Abid Mehmood · 2024

Detecting malicious insider threats is a critical concern for organizations due to the potential for significant damage and the subtle nature of such activities. Insider threats are inherently complex to identify because malicious actions often masquerade as legitimate behavior, making traditional detection methods insufficient. Current approaches frequently rely on limited data sources and fail to capture the multifaceted aspects of user behavior, leading to gaps in threat detection. In this paper, we propose a novel methodology that addresses these challenges by integrating advanced natural language processing techniques, statistical feature analysis, and psychometric profiling. We lever-age textual content from user communications and web activities, apply statistical analyses on temporal and frequency-based be-havioral data, and incorporate users' psychometric profiles based on OCEAN scores to create comprehensive behavioral profiles. An isolation forest model is utilized as an anomaly detector to identify malicious activities and the users responsible. Our iterative approach assesses the contribution of each data source to detection efficacy, and we employ dimensionality reduction techniques to refine feature importance. Experimental results demonstrate that our integrated model significantly outperforms existing methods, effectively enhancing the detection of malicious insider activities by addressing the limitations of current approaches.

Read the paper · More papers on PaperTik