<p>Insider threats represent a persistent and high-impact cybersecurity challenge due to their temporal complexity, contextual dependence, and ability to evade traditional perimeter defenses. User and Entity Behavior Analytics systems based on deep learning have demonstrated strong detection performance; however, most existing approaches remain accuracy-centric and produce deterministic predictions that fail to express confidence, limiting their operational reliability in real-world security environments. This study proposes an uncertainty-aware attention-based bidirectional Long Short-Term Memory framework that reframes insider threat detection as a risk-confidence co-estimation problem. The proposed model integrates an attention mechanism for contextual feature weighting with Monte Carlo Dropout to quantify epistemic uncertainty arising from limited data, behavioral evolution, and model incompleteness. A novel final risk score formulation combines prediction probability, epistemic uncertainty, and role-based contextual risk to support confidence-aware decision-making and user micro-segmentation. Experimental results demonstrated outstanding predictive capability with an Average Precision (AUPRC) of 0.9882, recall of 0.9450 at a 0.5 threshold, precision of 1.0000 on low-uncertainty samples, and a Brier Score of 0.0068, indicating excellent probability calibration and prediction reliability. Statistical validation further revealed strong separation between low-, medium-, and high-risk users, where high-risk users exhibited predicted probabilities approaching 1.0 with extremely low epistemic uncertainty, while medium-risk users demonstrated elevated uncertainty levels associated with ambiguous behavior patterns. Incorporating uncertainty into risk scoring supports reduction of unnecessary false-positive escalations and improves alignment with operational risk management practices. These findings establish epistemic uncertainty as an independent and operationally critical signal in insider threat detection and demonstrate that uncertainty-aware deep sequential modeling provides a more trustworthy foundation for Proactive Risk Management than accuracy-centric UEBA approaches.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Risk-confidence co-estimation in insider threat detection using uncertainty-aware deep sequential models for proactive risk management

  • Akampurira Paul,
  • Sadiq O. Bashir,
  • Buhari Dahiru,
  • Mandela Ngaira,
  • Maninti Venkateswarlu

摘要

Insider threats represent a persistent and high-impact cybersecurity challenge due to their temporal complexity, contextual dependence, and ability to evade traditional perimeter defenses. User and Entity Behavior Analytics systems based on deep learning have demonstrated strong detection performance; however, most existing approaches remain accuracy-centric and produce deterministic predictions that fail to express confidence, limiting their operational reliability in real-world security environments. This study proposes an uncertainty-aware attention-based bidirectional Long Short-Term Memory framework that reframes insider threat detection as a risk-confidence co-estimation problem. The proposed model integrates an attention mechanism for contextual feature weighting with Monte Carlo Dropout to quantify epistemic uncertainty arising from limited data, behavioral evolution, and model incompleteness. A novel final risk score formulation combines prediction probability, epistemic uncertainty, and role-based contextual risk to support confidence-aware decision-making and user micro-segmentation. Experimental results demonstrated outstanding predictive capability with an Average Precision (AUPRC) of 0.9882, recall of 0.9450 at a 0.5 threshold, precision of 1.0000 on low-uncertainty samples, and a Brier Score of 0.0068, indicating excellent probability calibration and prediction reliability. Statistical validation further revealed strong separation between low-, medium-, and high-risk users, where high-risk users exhibited predicted probabilities approaching 1.0 with extremely low epistemic uncertainty, while medium-risk users demonstrated elevated uncertainty levels associated with ambiguous behavior patterns. Incorporating uncertainty into risk scoring supports reduction of unnecessary false-positive escalations and improves alignment with operational risk management practices. These findings establish epistemic uncertainty as an independent and operationally critical signal in insider threat detection and demonstrate that uncertainty-aware deep sequential modeling provides a more trustworthy foundation for Proactive Risk Management than accuracy-centric UEBA approaches.