Machine Learning-Based Risky User Behavior Detection to Mitigate Ransomware Attacks on Higher Education Institutions
Open Access DepositedThis Praxis develops a machine learning (ML) model to address ransomware threats in higher education institutions (HEIs). HEIs are vulnerable to cyberattacks due to their open-access environments, diverse user bases, and decentralized IT systems. These vulnerabilities are compounded by limited budgets, heightened risks from increased digital operations, and a lack of security awareness among its users. The research focuses on the critical role of user behavior in cybersecurity strategies and utilizes ML to proactively detect risky user behaviors that could lead to ransomware attacks.Utilizing the CERT r4.2 Insider Threat dataset, this Praxis evaluates five ML models: Random Forest, Gradient Boosting, XGBoost, Support Vector Classifier, and Convolutional Neural Networks, to analyze user behaviors across email, HTTP, file access, device use, and logon activities. The research employs a dual-layer method. It initially identifies malicious activities in Layer 1, and then aggregates these activities to determine user risk levels in Layer 2. It utilizes K-means clustering to categorize users into various risk categories and utilizes Explainable Artificial Intelligence techniques such as SHapley Additive exPlanations to enhance transparency and interpretability. Key outcomes indicate that behaviors linked to device usage and HTTP actions are significant predictors of risky behaviors. While email content is impactful, it does not play as central a role as device and HTTP activities. The Random Forest ML model is effective in detecting these behaviors.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.