Electronic Thesis/Dissertation
 

Causal AI for Early Insider Threat Prevention Through Unsupervised Discovery of Behavioral Escalation Pathways

Open Access Deposited

(1) they do not provide any causal explanation to their predictions, (2) they only consider current anomalies, but do not model an employee's anomalous evolution over time, and (3) they assume that the behavior of different types of employees is the same, i.e., they do not consider a user's role in the organization. The three drawbacks lead to a high false positive rate, alert fatigue, and largely a reactive security posture. This praxis introduces a new Causal AI framework to identify traces of escalating insider threats from the data recorded by an enterprise in an unsupervised and role-based way without the need for labeled data. It uses the Peter Clark (PC) algorithm for causal structure learning to derive the causal graphs from the Carnegie Mellon CERT Insider Threat Dataset v4.2, to learn robust, multi-step behavioral patterns that are likely to lead to insider threat incidents. The role-specific causal patterns for Administrators and Non-Administrators are captured and psychological attributes are used as exogenous contextual anchors. The emphasis is changed from post-event detection to pre-event prevention with a focus on identifying users that are traversing along the causal paths leading to the manifestation of threats. Causal discovery, when used with an accumulation based risk model, can identify risk at an early enough stage that a significant number of lead days are afforded. This affords an organization the chance to engage in pre-event remediation, and this can be done without the explanatory, temporal, and contextual challenges present in current risk models. Further, this framework also demonstrates that causal relationships remain sufficiently consistent over time to allow them to be used in practice.

Insider threat is considered one of the most severe cyber threats, with an average detection and containment period of three months and an annual cost of more than $17M. Most existing detection techniques are anomaly-based with three major drawbacks

Author Language Keyword Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Smajlaj_gwu_0075A_17833.pdf Smajlaj_gwu_0075A_17833.pdf 2026-06-24 Open Access