An Ensemble Method for Insider Threat Detection Based on User Activities Analysis Using Bi-LSTM and GA Optimization
摘要
One of the main reasons why firms experience security breaches is insider threats. They are users or workers of an organization who carry out any malicious conduct with the intention of harming others. The majority of insider threat detection techniques currently in use depend on deep learning and machine learning techniques and have the following drawbacks: they need obvious feature engineering, which increases the number of false positives; they rely on established criteria or maintained patterns and fail to detect novel or unidentified threats they are highly computational and need a large amount of training data. For an improved client behavior-based insider threat identification system, this study proposes an integrated learning strategy to overcome the aforementioned limitations. An ensemble model Bidirectional long-short-term memory and uses a CNN, ANN with GA and Meta Learner also used to find the best solution by combining all models predictions. The first kernel selection for CNN is done using the fast global search method of the genetic algorithm.