A Review of Recent Advances, Challenges, and Opportunities in Malicious Insider Threat Detection Using Machine Learning Methods

被引:12
|
作者
Alzaabi, Fatima Rashed [1 ]
Mehmood, Abid [1 ]
机构
[1] Abu Dhabi Univ, Coll Engn, Abu Dhabi, U Arab Emirates
关键词
Insider threat detection; privilege escalation; anomaly detection; user action graph; cyber security; user behavior; temporal information; pre-trained language models; word embedding; CERT dataset;
D O I
10.1109/ACCESS.2024.3369906
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Insider threat detection has become a paramount concern in modern times where organizations strive to safeguard their sensitive information and critical assets from malicious actions by individuals with privileged access. This survey paper provides a comprehensive overview of insider threat detection, highlighting its significance in the current landscape of cybersecurity. The review encompasses a broad spectrum of methodologies and techniques, with a particular focus on classical machine-learning approaches and their limitations in effectively addressing the intricacies of insider threats. Furthermore, the survey explores the utilization of modern deep learning and natural language processing (NLP) based methods as promising alternatives, shedding light on their advantages over traditional methods. The comprehensive analysis of results from experiments utilizing NLP and large language models to detect malicious insider threats on the CMU CERT dataset reveals promising insights. Studies surveyed in this paper indicate that these advanced techniques demonstrate notable efficacy in identifying suspicious activities and anomalous behaviors associated with insider threats within organizational systems. Additionally, the survey underscores the potential of NLP and large language model-based approaches, which can enhance threat detection by deciphering textual and contextual information. In the conclusion section, the paper offers valuable insights into the future directions of insider threat detection. It advocates for the integration of more sophisticated time-series-based techniques, recognizing the importance of temporal patterns in insider threat behaviors. These recommendations reflect the evolving nature of insider threats and emphasize the need for proactive, data-driven strategies to safeguard organizations against internal security breaches. In conclusion, this survey not only underscores the urgency of addressing insider threats but also provides a roadmap for the adoption of advanced methodologies to enhance detection and mitigation capabilities in contemporary cybersecurity paradigms.
引用
收藏
页码:30907 / 30927
页数:21
相关论文
共 50 条
  • [41] Recent Advances in Adversarial Machine Learning: Status, Challenges and Perspectives
    Rawal, Atul
    Rawat, Danda B.
    Sadler, Brian
    ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING FOR MULTI-DOMAIN OPERATIONS APPLICATIONS III, 2021, 11746
  • [42] Recent advances and outstanding challenges for machine learning interatomic potentials
    Ko, Tsz Wai
    Ong, Shyue Ping
    NATURE COMPUTATIONAL SCIENCE, 2023, 3 (12): : 998 - 1000
  • [43] Recent advances and outstanding challenges for machine learning interatomic potentials
    Tsz Wai Ko
    Shyue Ping Ong
    Nature Computational Science, 2023, 3 : 998 - 1000
  • [44] Recent advances in the applications of machine learning methods for heat exchanger modeling-a review
    Zou, Junjia
    Hirokawa, Tomoki
    An, Jiabao
    Huang, Long
    Camm, Joseph
    FRONTIERS IN ENERGY RESEARCH, 2023, 11
  • [45] Exploring Feature Normalization and Temporal Information for Machine Learning Based Insider Threat Detection
    Ferreira, Pedro
    Le, Duc C.
    Zincir-Heywood, Nur
    2019 15TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2019,
  • [46] Recent advances in algal bloom detection and prediction technology using machine learning
    Park, Jungsu
    Patel, Keval
    Lee, Woo Hyoung
    SCIENCE OF THE TOTAL ENVIRONMENT, 2024, 938
  • [47] Deep Learning for Anomaly Detection: Challenges, Methods, and Opportunities
    Pang, Guansong
    Cao, Longbing
    Aggarwal, Charu
    WSDM '21: PROCEEDINGS OF THE 14TH ACM INTERNATIONAL CONFERENCE ON WEB SEARCH AND DATA MINING, 2021, : 1127 - 1130
  • [48] A review of recent advances and applications of machine learning in tribology
    Sose, Abhishek T. T.
    Joshi, Soumil Y. Y.
    Kunche, Lakshmi Kumar
    Wang, Fangxi
    Deshmukh, Sanket A. A.
    PHYSICAL CHEMISTRY CHEMICAL PHYSICS, 2023, 25 (06) : 4408 - 4443
  • [49] A Review of Machine Learning's Role in Cardiovascular Disease Prediction: Recent Advances and Future Challenges
    Naser, Marwah Abdulrazzaq
    Majeed, Aso Ahmed
    Alsabah, Muntadher
    Al-Shaikhli, Taha Raad
    Kaky, Kawa M.
    ALGORITHMS, 2024, 17 (02)
  • [50] Condition Monitoring using Machine Learning: A Review of Theory, Applications, and Recent Advances
    Surucu, Onur
    Gadsden, Stephen Andrew
    Yawney, John
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 221