A Review of Recent Advances, Challenges, and Opportunities in Malicious Insider Threat Detection Using Machine Learning Methods

dc.contributor.authorFatima, Alzaabi
dc.contributor.authorMehmood, Abid
dc.date.accessioned2024-08-23T05:58:44Z
dc.date.available2024-08-23T05:58:44Z
dc.date.issued2024-02-26
dc.descriptionInsider threat detection is a critical component of cybersecurity, primarily concerned with identifying and mitigating security risks originating from individuals with authorized access to an organization’s systems, data, or facilities. This domain has gained increasing significance due to the rising frequency and severity of insider threats, encompassing activities such as data theft, fraud, sabotage, and espionage by trusted insiders. Statistical evidence underscores the urgency of addressing this issue, with insider threats responsible for 35% data breaches in a 2023 Verizon Data Breach Investigations Report [1]. Malicious insider threats, in particular, inflict damage 20 times greater than external actors and incur an average cost of $ 4.5 million per breach.
dc.description.abstractInsider threat detection has become a paramount concern in modern times where organizations strive to safeguard their sensitive information and critical assets from malicious actions by individuals with privileged access. This survey paper provides a comprehensive overview of insider threat detection, highlighting its significance in the current landscape of cybersecurity. The review encompasses a broad spectrum of methodologies and techniques, with a particular focus on classical machine-learning approaches and their limitations in effectively addressing the intricacies of insider threats. Furthermore, the survey explores the utilization of modern deep learning and natural language processing (NLP) based methods as promising alternatives, shedding light on their advantages over traditional methods. The comprehensive analysis of results from experiments utilizing NLP and large language models to detect malicious insider threats on the CMU CERT dataset reveals promising insights. Studies surveyed in this paper indicate that these advanced techniques demonstrate notable efficacy in identifying suspicious activities and anomalous behaviors associated with insider threats within organizational systems. Additionally, the survey underscores the potential of NLP and large language model-based approaches, which can enhance threat detection by deciphering textual and contextual information. In the conclusion section, the paper offers valuable insights into the future directions of insider threat detection. It advocates for the integration of more sophisticated time-series-based techniques, recognizing the importance of temporal patterns in insider threat behaviors. These recommendations reflect the evolving nature of insider threats and emphasize the need for proactive, data-driven strategies to safeguard organizations against internal security breaches. In conclusion, this survey not only underscores the urgency of addressing insider threats but also provides a roadmap for the adoption of advanced methodologies to enhance detection and mitigation capabilities in contemporary cybersecurity paradigms. Keywords: anomaly detection, CERT dataset, cyber security, Insider threat detection, pre-trained language models, privilege escalation, en
dc.identifier.citationAlzaabi, F. R., & Mehmood, A. (2024). A review of recent advances, challenges, and opportunities in malicious insider threat detection using machine learning methods. IEEE Access, 12, 30907-30927.
dc.identifier.doihttps://doi.org/10.1109/ACCESS.2024.3369906
dc.identifier.urihttps://repository.adu.ac.ae/handle/1/6288
dc.language.isoen
dc.publisherInstitute of Electrical and Electronics Engineers Inc.
dc.titleA Review of Recent Advances, Challenges, and Opportunities in Malicious Insider Threat Detection Using Machine Learning Methods
dc.typeArticle

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
A Review of Recent Advances.pdf
Size:
1.64 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed to upon submission
Description:

Collections