With the growing dependence of organizations on digital infrastructures, the threat of insider cybersecurity breaches has become a significant worry. This study investigates how machine learning models perform in identifying insider threats, specifically examining the influence of feature selection through Recursive Feature Elimination (RFE). The models chosen for evaluation are Random Forest, SVM (One-Class), Isolation Forest, LSTM, and Autoencoder. The research methodology includes gathering a thorough dataset that encompasses various insider threat scenarios. The dataset contains features that include a range of behavioral, network, and system-related attributes. Two experimental setups are used: one involves feature selection using Recursive Feature Elimination (RFE) and the other does not use feature selection. Random Forest is utilized to assess the models’ performance due to its resilience and capability to manage varied datasets. SVM (One-Class) is evaluated for its effectiveness in detecting insider threats due to its ability to perform effectively in high-dimensional spaces. The Isolation Forest algorithm is used for anomaly detection to pinpoint uncommon patterns in the data. LSTM, a Recurrent Neural Network, and Autoencoder, a neural network architecture for unsupervised learning, are used to capture temporal dependencies and latent representations, respectively. The comparative analysis evaluates important performance metrics including precision, recall, F1-Score, and area under the receiver operating characteristic curve (AUC-ROC). The study seeks to assess how feature selection affects the effectiveness of each model, investigating whether eliminating irrelevant features improves or impairs the identification of insider threats. This research offers valuable insights into the strengths and weaknesses of the chosen machine learning models for detecting insider threats in cybersecurity. Organizations can analyze how feature selection affects the deployment of models to enhance their cybersecurity defenses against insider threats, helping them make well-informed decisions based on their unique needs and limitations.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Machine Learning for Insider Threat Detection in Cybersecurity—A Comparative Analysis

  • Rahul Sharma,
  • S. Nitin Sherje,
  • Shilpa Sharma,
  • Kiran Ahuja,
  • Vijay Marathe,
  • Dipika R. Birari

摘要

With the growing dependence of organizations on digital infrastructures, the threat of insider cybersecurity breaches has become a significant worry. This study investigates how machine learning models perform in identifying insider threats, specifically examining the influence of feature selection through Recursive Feature Elimination (RFE). The models chosen for evaluation are Random Forest, SVM (One-Class), Isolation Forest, LSTM, and Autoencoder. The research methodology includes gathering a thorough dataset that encompasses various insider threat scenarios. The dataset contains features that include a range of behavioral, network, and system-related attributes. Two experimental setups are used: one involves feature selection using Recursive Feature Elimination (RFE) and the other does not use feature selection. Random Forest is utilized to assess the models’ performance due to its resilience and capability to manage varied datasets. SVM (One-Class) is evaluated for its effectiveness in detecting insider threats due to its ability to perform effectively in high-dimensional spaces. The Isolation Forest algorithm is used for anomaly detection to pinpoint uncommon patterns in the data. LSTM, a Recurrent Neural Network, and Autoencoder, a neural network architecture for unsupervised learning, are used to capture temporal dependencies and latent representations, respectively. The comparative analysis evaluates important performance metrics including precision, recall, F1-Score, and area under the receiver operating characteristic curve (AUC-ROC). The study seeks to assess how feature selection affects the effectiveness of each model, investigating whether eliminating irrelevant features improves or impairs the identification of insider threats. This research offers valuable insights into the strengths and weaknesses of the chosen machine learning models for detecting insider threats in cybersecurity. Organizations can analyze how feature selection affects the deployment of models to enhance their cybersecurity defenses against insider threats, helping them make well-informed decisions based on their unique needs and limitations.