Detecting Insider Threat in Corporate Network using Hybrid Anomaly Detection Models — ICACNC 2026 | TechShield Publications
ICACNC 2026 · Conference Article

Detecting Insider Threat in Corporate Network using Hybrid Anomaly Detection Models

Authors: Muhammad Annas Manzoor, Muhamamd Usman Kashif, Sana Tariq, Aoun Muhammad

Abstract

Insider threats pose a significant risk in today’s business networks as malicious actions can be from trusted inside users. Conventional network intrusion detection systems (NIDS) may not be effective in detecting these attacks because of the complexity and dynamism of network traffic. This research introduces a hybrid anomaly detection model to detect insider threats in business settings with the help of the CICIDS2017 dataset. The proposed model integrates Random Forest, XGBoost and Isolation Forest algorithms to enhance the accuracy of detection and the ability of anomaly detection. The data was preprocessed to improve the reliability of the model and reduce overfitting by applying several techniques such as data cleaning, feature scaling, dimensionality reduction with PCA, balanced sampling, and noise injection. The model was trained and tested with various sets of network attack and normal traffic data. The experimental results showed that the proposed hybrid approach has excellent accuracy, precision, recall, F1-score, and ROC AUC with realistic and generalized evaluation results.

Insider Threat Detection Hybrid Anomaly Detection Random Forest XGBoost Isolation Forest CICIDS2017

Cite This Paper

M. A. Manzoor, M. U. Kashif, S. Tariq, and A. Muhammad, “Detecting Insider Threat in Corporate Network using Hybrid Anomaly Detection Models,” Proc. Int. Conf. on AI, Cybersecurity, and Next-Gen Computing (ICACNC 2026), The Government Sadiq College Women University Bahawalpur, Jul. 2026, doi: 10.67535/tsp.000003.021.