Unveiling Shadows: Harnessing Artificial Intelligence for Insider Threat Detection

Author:

Yilmaz ErhanORCID,Can OzguORCID

Abstract

Insider threats pose a significant risk to organizations, necessitating robust detection mechanisms to safeguard against potential damage. Traditional methods struggle to detect insider threats operating within authorized access. Therefore, the use of Artificial Intelligence (AI) techniques is essential. This study aimed to provide valuable insights for insider threat research by synthesizing advanced AI methodologies that offer promising avenues to enhance organizational cybersecurity defenses. For this purpose, this paper explores the intersection of AI and insider threat detection by acknowledging organizations' challenges in identifying and preventing malicious activities by insiders. In this context, the limitations of traditional methods are recognized, and AI techniques, including user behavior analytics, Natural Language Processing (NLP), Large Language Models (LLMs), and Graph-based approaches, are investigated as potential solutions to provide more effective detection mechanisms. For this purpose, this paper addresses challenges such as the scarcity of insider threat datasets, privacy concerns, and the evolving nature of employee behavior. This study contributes to the field by investigating the feasibility of AI techniques to detect insider threats and presents feasible approaches to strengthening organizational cybersecurity defenses against them. In addition, the paper outlines future research directions in the field by focusing on the importance of multimodal data analysis, human-centric approaches, privacy-preserving techniques, and explainable AI.

Publisher

Engineering, Technology & Applied Science Research

Reference39 articles.

1. J. R. C. Nurse et al., "Understanding Insider Threat: A Framework for Characterising Attacks," in 2014 IEEE Security and Privacy Workshops, San Jose, CA, USA, May 2014, pp. 214–228.

2. "Cyber security breaches survey 2023," Department for Science, Innovation & Technology, London, UK. [Online]. Available: https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2023/cyber-security-breaches-survey-2023.

3. I. Homoliak, F. Toffalini, J. Guarnizo, Y. Elovici, and M. Ochoa, "Insight Into Insiders and IT: A Survey of Insider Threat Taxonomies, Analysis, Modeling, and Countermeasures," ACM Computing Surveys, vol. 52, no. 2, Dec. 2019.

4. T. E. Senator et al., "Detecting insider threats in a real corporate database of computer usage activity," in Proceedings of the 19th ACM SIGKDD international conference on Knowledge discovery and data mining, Chicago, IL, USA, May 2013, pp. 1393–1401.

5. "Defining Insider Threats," CISA, https://www.cisa.gov/topics/physical-security/insider-threat-mitigation/defining-insider-threats.

Cited by 4 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. A Privacy Recommending Data Processing Model for Internet of Vehicles (IoV) Services;Engineering, Technology & Applied Science Research;2024-08-02

2. Enhancing Enterprise Financial Fraud Detection Using Machine Learning;Engineering, Technology & Applied Science Research;2024-08-02

3. Securing Cloud Computing Services with an Intelligent Preventive Approach;Engineering, Technology & Applied Science Research;2024-06-01

4. Towards Optimal NLP Solutions: Analyzing GPT and LLaMA-2 Models Across Model Scale, Dataset Size, and Task Diversity;Engineering, Technology & Applied Science Research;2024-06-01

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3