Machine Learning to Accelerate Insider Attack Detection
Open Access DepositedIncreasing volumes of user logs delays an organization’s ability to identify and respond to insider attacks. This increases their incident response times and incurs significant financial costs and reputational damage. In this praxis, we address this challenge by accelerating the detection of insider attacks with an accurate machine learning model. This research identifies critical features for classifying insider attacks, develops and tunes three ML models (RF, XGB, and LGBM), and compares their results for accuracy and execution time. The findings confirm that user file activity, USB device connections, Internet browser history, and email records are significant features to detect insider attacks. Among the three ML models examined, LGBM outperformed the rest, achieving the highest accuracy and efficiency with the fastest execution time, making it the most suitable ML method to accelerate the detection of insider attacks. This praxis adds to the existing knowledge by demonstrating that the LGBM model, previously unexplored for the application of insider attack detection using the CMU CERT r4.2 dataset, is faster and more accurate than previously researched ML models. It also highlights the importance of execution time in evaluating ML models for accelerating insider attack detection. Furthermore, this praxis underscores the need for comprehensive feature engineering, informed by domain experts, to capture complex user behaviors indicative of insider attacks.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.