Detecting Insider Threat in Corporate Network using Hybrid Anomaly Detection Models
Authors: Muhammad Annas Manzoor, Muhamamd Usman Kashif, Sana Tariq, Aoun Muhammad
Abstract
Insider threats pose a significant risk in today’s business networks as malicious actions can be from trusted inside users. Conventional network intrusion detection systems (NIDS) may not be effective in detecting these attacks because of the complexity and dynamism of network traffic. This research introduces a hybrid anomaly detection model to detect insider threats in business settings with the help of the CICIDS2017 dataset. The proposed model integrates Random Forest, XGBoost and Isolation Forest algorithms to enhance the accuracy of detection and the ability of anomaly detection. The data was preprocessed to improve the reliability of the model and reduce overfitting by applying several techniques such as data cleaning, feature scaling, dimensionality reduction with PCA, balanced sampling, and noise injection. The model was trained and tested with various sets of network attack and normal traffic data. The experimental results showed that the proposed hybrid approach has excellent accuracy, precision, recall, F1-score, and ROC AUC with realistic and generalized evaluation results.
