An Anomaly-Based Machine Learning Approach for Insider Threat Detection and Mitigation
Open Access DepositedThe threat posed by malicious insiders is becoming more severe with each passing day, leading to significant consequences for organizations across various sectors. These threats not only result in substantial financial losses but also inflict serious reputational damage, eroding trust among the general public. The impact of these threats has compelled organizations to prioritize their defenses against insider threats and have made it essential for companies to invest in more robust security measures based on machine learning. This praxis aims to develop machine learning models capable of identifying and classifying malicious threats in a timely manner. The research uses Computer Emergency Response Team’s session r5.2 dataset to validate machine learning models. The dataset comprises 1,004,462 records and 228 features of both normal and malicious insiders. This dataset is highly imbalanced and very large. The praxis builds and compares three ML models in terms of their performance and detection speed and selects one of the ML models out of the three models: Random Forest, Extreme Gradient Boosting (XGBoost), and Gradient Boosting. One of the primary results of this research indicate that out of the various sampling techniques examined, SMOTE proved to be the most effective method for addressing the extreme imbalance in the r5.2 dataset. Another key achievement of this research is the finding that n_concurrent_sessions, usb_mean_usb_dur, and ITAdmin are among the most influential features in the dataset. More importantly, the research found that XGBoost outperformed both Random Forest and Gradient Boosting models in terms of predictive capabilities and detection speed.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.