Abstract
Detecting insider threats isn’t easy, mainly because the users involved already have legitimate access to organizational systems. This makes it hard to tell the difference between normal, everyday activity and actions that could actually be harmful. Many traditional methods depend on fixed rules or basic anomaly detection, but these often fail to notice the slow, subtle changes in behavior that develop over time. In this study, a behavior-aware insider threat detection framework is introduced that focuses on how user activity evolves over time, rather than trying to interpret intentions or psychological factors. The system continuously monitors key activities such as login patterns, access frequency and session behavior and uses this information to generate a dynamic risk score for each user. Simply put, it compares what a user is doing now with their usual behavior and looks for consistent changes that could signal potential risk. To make detection more reliable, the framework includes a threshold-based alert mechanism. Instead of reacting to one-off unusual actions, it generates alerts only when changes in behavior persist over time. This helps cut down on false alarms and ensures that alerts are more meaningful and useful for security teams. The framework was tested using simulated behavioral data and the results show that this time-based risk scoring approach can effectively distinguish between normal and suspicious behavior. Overall, the findings highlight how important it is to analyze behavior over time when trying to detect insider threats early. The system is also designed to be scalable, making it well-suited for high-security environments such as defense organizations and critical infrastructure systems.
Keywords
Insider Threat Detection Behavioral Analysis Risk Scoring Temporal Analysis CybersecurityReferences
- 1. , “Deep learning for insider threat detection: Review, challenges and opportunities,” Computers & Security, vol. 104, pp. 1–15, 2021.
- 2. , “A review of insider threat detection: Classification, machine learning techniques, datasets and challenges,” Applied Sciences, vol. 10, no. 15, art. no. 5208, 2020.
- 3. , “Behavioral based insider threat detection using deep learning,” IEEE Access, vol. 9, pp. 67220–67230, 2021.
- 4. , “Insider threat detection based on deep clustering of multi-source behavioral events,” Applied Sciences, vol. 13, no. 24, art. no. 13021, 2023.
- 5. , “Detection and prediction of insider threats to cyber security: A systematic literature review and meta-analysis,” Big Data Analytics, vol. 1, art. no. 6, 2016.
- 6. , “Temporal activity modeling for insider threat detection using LSTM networks,” Journal of Information Security and Applications, vol. 70, art. no. 103152, 2023.
- 7. , “Graph neural networks for insider threat detection,” ACM Transactions on Privacy and Security, vol. 26, no. 4, pp. 17:1–17:24, 2023.
- 8. , “Insider threat detection using graph-based approaches,” Journal of Applied Security Research, vol. 4, no. 1, pp. 32–81, 2009.
- 9. , “User behavior analytics for insider threat detection,” Future Generation Computer Systems, vol. 97, pp. 678–688, 2019.
- 10. , “Cybersecurity insider threat detection using data mining,” Computers & Security, vol. 85, pp. 1–14, 2019.
- 11. , “Insider threat detection using machine learning,” Journal of Cyber Security Technology, vol. 2, no. 3, pp. 123–145, 2018.
- 12. , “Insider threat detection techniques: A survey,” Journal of Computer Security, vol. 23, no. 4, pp. 1–30, 2015.
- 13. , “Behavior rule specification-based intrusion detection,” IEEE Transactions on Dependable and Secure Computing, vol. 12, no. 4, pp. 439–453, 2015.
- 14. , “Insider threat prediction tool,” Computers & Security, vol. 21, no. 1, pp. 62–73, 2002.
- 15. , “User behavior modeling for insider threat detection,” Expert Systems with Applications, vol. 41, no. 8, pp. 3933–3941, 2014.
- 16. , “A hybrid ML approach for real time insider threat detection,” IEEE Transactions on Dependable and Secure Computing, 2024.
- 17. , “Deep learning for unsupervised insider threat detection,” in Proc. AAAI Workshops, 2017.
- 18. , “Modeling user search behavior for insider threat detection,” IEEE Security & Privacy, vol. 9, no. 4, pp. 22–28, 2011.
- 19. , “A Bayesian network model for insider threat detection,” in Proc. IEEE Security & Privacy Workshops, 2013, pp. 82–89.
- 20. , “Bridging the gap: Behavior-based insider threat detection,” IEEE Security & Privacy, vol. 11, no. 1, pp. 34–42, 2013.
- 21. , “Unsupervised learning for insider threat detection,” in Proc. ACM SIGKDD Int. Conf. Knowl. Discovery Data Mining, 2011.
- 22. , “An overview of anomaly detection techniques,” Computer Networks, vol. 51, no. 12, pp. 3448–3470, 2007.
- 23. , “Anomaly detection: A survey,” ACM Computing Surveys, vol. 41, no. 3, art. no. 15, 2009.
- 24. , “An intrusion detection model,” IEEE Transactions on Software Engineering, vol. SE-13, no. 2, pp. 222–232, 1987.
- 25. , “Hybrid anomaly detection framework for insider threats,” Security and Communication Networks, vol. 2020, 2020.
- 26. , “Sequence learning for insider threat detection,” IEEE Access, vol. 8, pp. 134160–134172, 2020.
- 27. , “Insider threat detection using contextual analysis,” Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications, 2015.
- 28. , “Discovering structural anomalies in graph-based data,” Data Mining and Knowledge Discovery, vol. 15, no. 3, pp. 331–354, 2007.
- 29. CERT Insider Threat Dataset, Software Engineering Institute, Carnegie Mellon University, Pittsburgh, PA, USA.
- 30. , Honeypots: Tracking Hackers. Boston, MA, USA: Addison-Wesley, 2003.
- 31. , “A review of recent advances, challenges, and opportunities in malicious insider threat detection using machine learning methods,” IEEE Access, vol. 12, pp. 30907–30927, 2024.
- 32. , “Insights into user behavioral-based insider threat detection: Systematic review,” International Journal of Information Security, 2025.
- 33. , “A review of the insider threat, a practitioner perspective within the U.K. financial services,” IEEE Access, vol. 12, 2024.
- 34. , “A taxonomic classification of insider threats: Existing techniques, future directions & recommendations,” Journal of Cyber Security and Mobility, vol. 12, no. 2, 2023.
- 35. , “DPI-ITD: A dual-perspective information-driven framework for insider threat detection in IoT systems,” IEEE Internet of Things Journal, vol. 12, no. 19, 2025.