Exploring Techniques for Detecting Insider Threats: A Comprehensive Review
摘要
Insider threats refer to malicious activities carried out by authorized users, including theft of intellectual property or security information, fraud, and sabotage. Within the realm of cybersecurity, the Internet is plagued by a vast number of cyberattacks, among which the insider threat stands out as one of the most formidable challenges. Identifying insiders (attackers) poses a significant challenge within organizations, as differentiating between benign employees and potential insiders is crucial. Surprisingly, the most damaging cyberattacks often originate from trusted insiders rather than external malicious actors or malware. The advantage insiders possess over external elements lies in their ability to circumvent security checks and operate undetected, posing a grave risk to organizational assets. When an insider, who is also considered an employee of a corporation, can inflict harm upon the business, they become a significant threat. The insider threat has emerged as a critical issue within organizations, resulting in the loss of information, confidential data, and trust. This paper aims to analyze the existing insider threat detection techniques and propose machine learning as a potential new approach.