MARATTO

article · Southern African Journal of Security

Detecting Malicious Insider Threats through Anomaly-Based User Behaviour Analytics in Enterprise Networks: Machine Learning Approach

Abstract

Detecting malicious insider threats within enterprise networks is essential for robust cybersecurity. Insiders with authorised access present significant risks that traditional security measures often fail to address. This paper explores the application of anomaly-based User Behavior Analytics (UBA) to identify these threats by examining a comprehensive dataset of user activities. The study assesses the performance of three machine learning models: Isolation Forest, One-Class SVM, and Autoencoder. Rigorous evaluation demonstrates the Autoencoder model’s superior performance compared to other models, as evidenced by higher precision, recall, F1-score, and ROC-AUC metrics. These findings underscore the Autoencoder’s effectiveness in accurately detecting insider threats, highlighting its potential as a valuable tool in enhancing enterprise network security. The results indicate that leveraging anomaly-based UBA with advanced machine learning techniques can significantly improve the detection and mitigation of insider threats, providing a more proactive and efficient approach to safeguarding sensitive information within organisations.

Research topics

  • Information and Cyber Security
  • Network Security and Intrusion Detection
  • Software System Performance and Reliability

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.25159/3005-4222/18099

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.