Insider threats are one of the toughest challenges in cybersecurity. Insider attacks can be particularly dangerous because they often go unnoticed and can lead to serious problems like data breaches, financial losses, and damage to a company’s reputation. This issue has become even more pressing in recent years with the rise of digital operations and remote work. Researchers have shown how machine learning can help predict these insider threats. While supervised learning models have shown great accuracy in identifying threats in certain datasets, they face a major hurdle: there simply isn’t enough labeled data on insider threats. On the other hand, unsupervised learning methods can spot unusual behavior and reveal hidden threats, but they often produce false alarms. Deep learning techniques could potentially offer better accuracy, but they require a lot of computing power and large amounts of training data. There are also exciting new trends in the field, such as behavioral biometrics, hybrid models, and explainable AI. However, challenges like inconsistent evaluation metrics and the difficulty of applying these models across different organizations still exist. This review aims to bring together existing research and pinpoint key areas that need more attention, providing a roadmap for future studies. By addressing issues like the need for standardized datasets, encouraging collaboration across different fields, and incorporating contextual data from organizations, this paper seeks to help future researchers create more effective and adaptable models for predicting insider threats.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Insider Threat Prediction Using Machine Learning Techniques: A Literature Review

  • Ashok Kumar,
  • Sanjeev Patwa,
  • Sunil Kumar Jangir

摘要

Insider threats are one of the toughest challenges in cybersecurity. Insider attacks can be particularly dangerous because they often go unnoticed and can lead to serious problems like data breaches, financial losses, and damage to a company’s reputation. This issue has become even more pressing in recent years with the rise of digital operations and remote work. Researchers have shown how machine learning can help predict these insider threats. While supervised learning models have shown great accuracy in identifying threats in certain datasets, they face a major hurdle: there simply isn’t enough labeled data on insider threats. On the other hand, unsupervised learning methods can spot unusual behavior and reveal hidden threats, but they often produce false alarms. Deep learning techniques could potentially offer better accuracy, but they require a lot of computing power and large amounts of training data. There are also exciting new trends in the field, such as behavioral biometrics, hybrid models, and explainable AI. However, challenges like inconsistent evaluation metrics and the difficulty of applying these models across different organizations still exist. This review aims to bring together existing research and pinpoint key areas that need more attention, providing a roadmap for future studies. By addressing issues like the need for standardized datasets, encouraging collaboration across different fields, and incorporating contextual data from organizations, this paper seeks to help future researchers create more effective and adaptable models for predicting insider threats.