Insider Threat Detection: Using Classification Models

Insider threats refer to cyber-attacks originating from within an organization that can cause significant damage, such as intellectual property theft, sabotage, and sensitive data exposure. Traditional cybersecurity strategies tend to focus on external threats, leaving organizations vulnerable to insider attacks. In this paper, we propose an approach for insider threat classification with various classification models. Aggregated numerical features are generated using the access patterns of the employees of the organization. We used the CERT dataset for training and testing. The proposed method is evaluated with classification models like Logistic Regression, Decision Tree, Random Forest, and Xgboost. The experimental results of the model's performance, measured using evaluation metrics such as accuracy, recall, precision, and F1-Score, demonstrated improved accuracy and performance compared to existing works in terms of high recall, precision, and F1-Score values, and effectively outperformed pre-trained CNN models.

Paper

Full text

PDF

Insider Threat Detection: Using Classification Models

Semantic Scholar · Computer Science · 2023

Abstract

Insider threats refer to cyber-attacks originating from within an organization that can cause significant damage, such as intellectual property theft, sabotage, and sensitive data exposure. Traditional cybersecurity strategies tend to focus on external threats, leaving organizations vulnerable to insider attacks. In this paper, we propose an approach for insider threat classification with various classification models. Aggregated numerical features are generated using the access patterns of the employees of the organization. We used the CERT dataset for training and testing. The proposed method is evaluated with classification models like Logistic Regression, Decision Tree, Random Forest, and Xgboost. The experimental results of the model's performance, measured using evaluation metrics such as accuracy, recall, precision, and F1-Score, demonstrated improved accuracy and performance compared to existing works in terms of high recall, precision, and F1-Score values, and effectively outperformed pre-trained CNN models.

Similar papers

© 2026 NYSGPT2525 LLC