• Home
  • Search
  • Modelling of Insider Threat Detection Based on Anomalous Behaviour of Users for Cyber Security
  • https://doi.org/10.1109/icsit65336.2025.11295003Copy DOI Icon

Modelling of Insider Threat Detection Based on Anomalous Behaviour of Users for Cyber Security

  • Aug 22, 2025
  • Nitin Barsagde +1 more
Show More
  • Abstract
  • Literature Map
  • References
  • Similar Papers
Abstract

Insider threats pose a significant challenge to organizations, as malicious activities often mimic legitimate user behavior and bypass traditional security mechanisms. This paper presents a novel hybrid framework for insider threat detection based on anomalous user behavior analysis using multi-source log data. Detection of insider threats is a significant concern in the realm of cybersecurity. Insiders pose the greatest threat due to their unique access. Insider risks can be identified by the atypical activity of a user. The individual is engaged at his place of employment. All user activity on the device is recorded. The recorded data is utilized to analyze user behaviour and identify unusual activities. The user's log, device, and file data were curated, sanitized, and standardized in this study. Features are derived from insider log data. The statistical analysis has been conducted to determine the central tendency and dispersion of the data. It facilitated the classification of normative and abnormal user activity. The interrelationship between the user and the PC is depicted in an undirected bipartite graph. Anomalous user behaviour is analyzed for insider risks based on data. Significant risk mitigation measures may be implemented when the user is identified as a potential insider threat. A medium risk rating is established when the user is identified as anomalous in 50 percent of insider threat activities. Low-level risk measures are implemented against the user upon a determination of guilt in 25 percent of potential risk activities. The measures used against the user include warnings, penalties, account suspension, termination, and reporting to management for additional action on the insider danger about their risk level.

Similar Papers
  • Research Article
  • Citations77

A new intelligent multilayer framework for insider threat detection

  • Nov 22, 2021
  • Computers and Electrical Engineering
  • Mohammed Nasser Al-Mhiqani +6
  • Conference Article
  • Citations10

GRU and Multi-autoencoder based Insider Threat Detection for Cyber Security

  • Oct 01, 2021
  • Fanzhi Meng +5
  • Conference Article
  • Citations16

Exploring Adversarial Properties of Insider Threat Detection

  • Jun 01, 2020
  • Duc C Le +1
  • Research Article
  • Citations22

Deep Learning and Dempster-Shafer Theory Based Insider Threat Detection

  • Oct 09, 2020
  • Mobile Networks and Applications
  • Zhihong Tian +6
  • PDF
  • Research Article
  • Citations117

Impact and Key Challenges of Insider Threats on Organizations and Critical Businesses

  • Sep 07, 2020
  • Electronics
  • Neetesh Saxena +5
  • Conference Article
  • Citations2

Personalized User Profiles-based Insider Threat Detection for Distributed File System

  • Dec 01, 2022
  • Wu Xin +5
  • Research Article
  • Citations124

Anomaly Detection for Insider Threats Using Unsupervised Ensembles

  • Apr 09, 2021
  • IEEE Transactions on Network and Service Management
  • Duc C Le +1
  • Research Article
  • Citations34

Insider threat detection in cyber-physical systems: a systematic literature review

  • Jul 26, 2024
  • Computers and Electrical Engineering
  • Mohammed Nasser Al-Mhiqani +5
  • Research Article
  • Citations34

Robust Anomaly-Based Insider Threat Detection Using Graph Neural Network

  • Sep 01, 2023
  • IEEE Transactions on Network and Service Management
  • Junchao Xiao +5
  • Book Chapter
  • Citations3

Insider Threat Prevention, Detection and Mitigation

  • Jan 01, 2009
  • Robert F Mills +2
  • Research Article
  • Citations4

Insider threat mitigation through human intelligence and counterintelligence: A case study in the shipping industry

  • Mar 02, 2024
  • Defense and Security Studies
  • Anastasios-Nikolaos Kanellopoulos
  • Book Chapter

Hybrid AI Architectures Combining ML and DL for Insider Threat Detection S.

  • Nov 18, 2025
  • S Sivakumar +2
  • Preprint Article

Leveraging Graph Neural Networks for Enhanced Insider Threat Detection in Enterprise Systems

  • Jun 04, 2025
  • Hemanth Ravipati
  • Conference Article
  • Citations70

Exploring Feature Normalization and Temporal Information for Machine Learning Based Insider Threat Detection

  • Oct 01, 2019
  • Pedro Ferreira +2
  • Book Chapter
  • Citations5

Anomaly Detection for Insider Threats: An Objective Comparison of Machine Learning Models and Ensembles

  • Jan 01, 2021
  • Filip Wieslaw Bartoszewski +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.