A Theory-Based Deep Learning Approach for Insider Threat Detection and Classification

dc.contributor.authorWanyonyi, Everleen Nekesa
dc.contributor.authorMasinde, Newton Wafula
dc.contributor.authorAbeka, Silvance Onyango
dc.date.accessioned2025-10-28T12:09:43Z
dc.date.issued2025-06-25
dc.description.abstractInsider threats are a substantial concern to organizational security, often leading to grave financial and reputational damage. Classical insider threat detection methods rely on predefined rules and signatures and struggle to keep pace with these attacks' sophisticated and evolving nature leading to dismal performances. This research introduces a deep learning-based approach for insider threat detection, leveraging user network behavior as the primary data source. Our technology detects deviations in user network activity that might indicate harmful insider activities. We use a Gated Recurrent Network (GRU) that captures user behavior's temporal and spatial characteristics. The proposed model is validated using a synthetic CERT r4.2 dataset and exhibits higher detection rates based on accuracy, Recall, Precision, and f-measure. Additionally, the Social Bond Theory (SBT) and the Situational Crime Prevention Theory (SCPT) are used to elaborate effective ways to control insider threats. This study also presents solutions for dataset imbalance and high dimensionality that adversely hinder common insider threat datasets from giving accurate predictions during model training and validation. Our findings show that deep learning and data preprocessing approaches can considerably improve the ability to detect insider threats, giving organizations a reliable defense mechanism against insider threats.
dc.identifier.citationWanyonyi, Everleen and Masinde, Newton and Abeka, Silvance, A Theory-Based Deep Learning Approach for Insider Threat Detection and Classification (November 25, 2024). Available at SSRN: https://ssrn.com/abstract=5319130 or http://dx.doi.org/10.2139/ssrn.5319130
dc.identifier.issn2319–8656
dc.identifier.urihttps://ir.jooust.ac.ke/handle/123456789/15188
dc.language.isoen
dc.publisherInternational Journal of Computer Applications Technology and Research
dc.subjectThreat Detection
dc.subjectTheory-Based
dc.subjectInformation Security
dc.subjectDeep Learning
dc.subjectGated Recurrent Unit
dc.subjectNetwork Behavior
dc.titleA Theory-Based Deep Learning Approach for Insider Threat Detection and Classification
dc.typeArticle

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Wanyonyi_ A Theory-Based Deep Learning Approach for Insider Threat Detection and Classification.pdf
Size:
334.77 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: