Insider Threat Pattern Detection Using Deep Learning to Evaluate Cyber Value at Risk (CVaR)
Prashant Vajpayee, Chittal Karuppiah, Gahangir Hossain · 2025
In an era marked by rapid advancements in information technology, automation has become an integral part of organizational workflows. However, alongside these technological strides, the challenge of data leakage due to insider threats has intensified. Authorized users, while entrusted with privileges, may inadvertently or maliciously compromise sensitive information. Such actions can lead to significant data loss and potentially harm an organization's reputation. In the realm of cybersecurity, insider threats emerge as a formidable adversary. These threats originate from individuals who hold legitimate access to computer networks and systems but exploit their privileges for nefarious purposes. Their actions span a spectrum of malevolence, including IP theft, sabotage, sensitive data exposure, and web application attacks. This paper will discuss the deep learning techniques, which offer a promising avenue for addressing insider threats. It provides an approach to analyze user behavior pattern using rule based deep learning algorithms for identifying abnormal user access to cyber assets indicative of insider threats. Further, the study will discuss the concept of Cyber- Value-at-Risk (CVaR) to quantify the risk due to insider threat originated via various users' activities, accesses, and anomalous behaviors. While study elaborates utilization of deep learning to leverage synthetic data for uncovering hidden patterns and anomalies, it will also discuss the challenges related to dataset availability, privacy, true positives, and false negatives. The fusion of deep learning, insider threat detection, and cyber risk management holds immense potential for safeguarding digital assets and maintaining the integrity of cyberspace. The paper explains limitations and shares future directions for extended research in this context.