Zurück zu den Ergebnissen
Bibliografischer Datensatz · Ansicht und Zugriff
Artículo

Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches

Sellappan Palaniappan et al · MMU Press · 2025

Open-Access-Volltext
Schnellübersicht. Prüfen Sie die grundlegenden Angaben und öffnen Sie den Inhalt über die Hauptschaltfläche. Die Seite zeigt nur die Informationen, die zum Identifizieren, Zitieren und Öffnen des Werks nötig sind.

Zugriff auf die Ressource

Öffnen Sie den Inhalt über die Hauptoption oder wählen Sie eine andere verfügbare Quelle.

DOAJ DOAJ Articles
Entrar por DOAJ
Hauptzugriff

Open-Access-Volltext

Texto completo identificado como acceso abierto.
Text öffnen
Otras opciones de acceso Elegí el proveedor disponible para esta ficha.
DOAJ CSV Export DOAJ - Open Access Journals
Acceder por DOAJ CSV Export
Importación CSV DOAJ - Open Access Journals
Acceder por Importación CSV
DOAJ OAI-PMH DOAJ Articles
Acceder por DOAJ OAI-PMH

Weitere verfügbare Optionen

Ist die Ressource auf mehreren Plattformen verfügbar, können Sie auswählen, wo sie geöffnet wird.

DOAJ CSV Export DOAJ - Open Access Journals Zugriff verfügbar
Öffnen
Importación CSV DOAJ - Open Access Journals Zugriff verfügbar
Öffnen
DOAJ OAI-PMH DOAJ Articles Zugriff verfügbar
Öffnen

Übersicht

Descripción general del contenido del recurso.

Insider threats pose a significant and growing risk to organizational cybersecurity, with recent studies indicating a 47% increase in insider incidents from 2018 to 2022. This paper presents a comparative analysis of unsupervised and supervised machine learning approaches for detecting potential insider threats through network traffic anomaly identification. We develop and evaluate an Isolation Forest (unsupervised) and a Random Forest (supervised) model, training them on a simulated dataset representing six months of network logs from a mid-sized company. Our study introduces a unique feature set combining traditional network metrics with temporal and behavioral indicators, enhancing the models' detection capabilities. Results show that the Random Forest classifier outperforms the Isolation Forest, with F1-scores of 0.6425 and 0.4624, respectively. However, the unsupervised approach shows promise in scenarios lacking labeled data. Key findings reveal that increased connection frequency and data transfer volume are critical indicators of potential threats, with temporal patterns also playing a significant role. This study provides valuable insights into the strengths and limitations of each approach, offering practical implications for real-world digital forensics investigations. We contribute to the field by proposing a hybrid approach that leverages the strengths of both methods, potentially improving the accuracy and adaptability of insider threat detection systems. These findings pave the way for more robust, context-aware cybersecurity measures in the digital age.

Zitieren

Elegí el formato que necesitás y copiá la referencia al portapapeles.

APA 7

al, S. P. E. (2025). Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches. https://doi.org/10.33093/jiwe.2025.4.2.10

MLA

al, Sellappan Palaniappan et. "Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches." 2025. https://doi.org/10.33093/jiwe.2025.4.2.10.

Chicago

al, Sellappan Palaniappan et. 2025. "Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches.". https://doi.org/10.33093/jiwe.2025.4.2.10.

Harvard

al, S. P. E. 2025, Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches, MMU Press, available at: https://doi.org/10.33093/jiwe.2025.4.2.10 [Accessed 10 Aug. 2026].

Teilen und drucken

Speichern Sie den Datensatz, kopieren Sie den Permalink oder drucken Sie ihn als PDF.

Referenz exportieren

Exportieren Sie den Datensatz in gängigen Formaten für Literaturverwaltungsprogramme.

Ressourcendetails

Bibliografische Angaben zur Prüfung, ob es sich um das richtige Material handelt.

Titel
Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches
Autor / Mitwirkende
Sellappan Palaniappan et al
Verlag
MMU Press
Erscheinungsjahr
2025
ISSN
2821-370X
ISSN
2821-370X
Sprache
Inglés

Schlagwörter

Entdecken Sie über diese Schlagwörter weitere verwandte Ressourcen.

Kopiert