Volver a resultados
Ficha bibliográfica · Consulta y acceso
Artículo

Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches

Sellappan Palaniappan et al · MMU Press · 2025

Acceso abierto al texto completo
Lectura rápida. Revisá los datos básicos del recurso y luego accedé al contenido desde el botón principal. En esta ficha solo se muestra la información necesaria para identificar la obra, citarla y abrirla.

Acceso al recurso

Entrá al contenido desde la opción principal o elegí otra fuente disponible.

DOAJ DOAJ Articles
Entrar por DOAJ
Acceso principal

Acceso abierto al texto completo

Texto completo identificado como acceso abierto.
Abrir texto
Otras opciones de acceso Elegí el proveedor disponible para esta ficha.
DOAJ CSV Export DOAJ - Open Access Journals
Acceder por DOAJ CSV Export
Importación CSV DOAJ - Open Access Journals
Acceder por Importación CSV
DOAJ OAI-PMH DOAJ Articles
Acceder por DOAJ OAI-PMH

Otras opciones disponibles

Si el recurso aparece en más de una plataforma, podés elegir dónde abrirlo.

DOAJ CSV Export DOAJ - Open Access Journals Acceso disponible
Abrir
Importación CSV DOAJ - Open Access Journals Acceso disponible
Abrir
DOAJ OAI-PMH DOAJ Articles Acceso disponible
Abrir

Resumen

Descripción general del contenido del recurso.

Insider threats pose a significant and growing risk to organizational cybersecurity, with recent studies indicating a 47% increase in insider incidents from 2018 to 2022. This paper presents a comparative analysis of unsupervised and supervised machine learning approaches for detecting potential insider threats through network traffic anomaly identification. We develop and evaluate an Isolation Forest (unsupervised) and a Random Forest (supervised) model, training them on a simulated dataset representing six months of network logs from a mid-sized company. Our study introduces a unique feature set combining traditional network metrics with temporal and behavioral indicators, enhancing the models' detection capabilities. Results show that the Random Forest classifier outperforms the Isolation Forest, with F1-scores of 0.6425 and 0.4624, respectively. However, the unsupervised approach shows promise in scenarios lacking labeled data. Key findings reveal that increased connection frequency and data transfer volume are critical indicators of potential threats, with temporal patterns also playing a significant role. This study provides valuable insights into the strengths and limitations of each approach, offering practical implications for real-world digital forensics investigations. We contribute to the field by proposing a hybrid approach that leverages the strengths of both methods, potentially improving the accuracy and adaptability of insider threat detection systems. These findings pave the way for more robust, context-aware cybersecurity measures in the digital age.

Cómo citar

Elegí el formato que necesitás y copiá la referencia al portapapeles.

APA 7

al, S. P. E. (2025). Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches. https://doi.org/10.33093/jiwe.2025.4.2.10

MLA

al, Sellappan Palaniappan et. "Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches." 2025. https://doi.org/10.33093/jiwe.2025.4.2.10.

Chicago

al, Sellappan Palaniappan et. 2025. "Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches.". https://doi.org/10.33093/jiwe.2025.4.2.10.

Harvard

al, S. P. E. 2025, Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches, MMU Press, available at: https://doi.org/10.33093/jiwe.2025.4.2.10 [Accessed 10 Aug. 2026].

Compartir e imprimir

Guardá la ficha, copiá su enlace permanente o imprimila como PDF.

Exportar referencia

Si usás un gestor bibliográfico, podés exportar el registro en los formatos más comunes.

Detalles del recurso

Información bibliográfica útil para confirmar que se trata del material correcto.

Título
Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches
Autor / colaboradores
Sellappan Palaniappan et al
Editorial
MMU Press
Año de publicación
2025
ISSN
2821-370X
ISSN
2821-370X
Idioma
Inglés

Materias

Explorá otros recursos relacionados a partir de estas materias.

Copiado