MARATTO

article

Performance Evaluation Framework for Insider Threat Detection Using Machine Learning

20241 citationHelwan University

Abstract

Nowadays, malicious behavior identification is considered a significant and challenging issue in cybersecurity. To mitigate this problem, an effective detection system can be a promising candidate to facilitate precise and rapid detection of a malicious insider. In this paper, a performance evaluation framework for insider threat detection using machine learning is proposed. This framework employs the effects of several machine learning models to assist in identifying insider threats. The proposed framework applied XGboost, SVM, RF, KNN, MLP, and LR to detect insider threats. The machine learning framework is evaluated across the CERT r5.2 dataset. After that, the results of these models are compared with evaluation metrics to determine which model is the most effective for insider detection at different granularity levels. Furthermore, we have empirically shown that XGBoost outperforms competitive algorithms and can achieve a range precision of 95.24%-97.85%, recall of 97.34%-99.30%, F1 score of 96.79%-98.81 %, and an AUC of 97.04%-98.63% for insider detection.

Research topics

  • Network Security and Intrusion Detection
  • Advanced Malware Detection Techniques
  • Information and Cyber Security

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/imsa61967.2024.10652829

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.