Back to results
Bibliographic record · Consultation and access
Artículo

Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches

Sellappan Palaniappan et al · MMU Press · 2025

Open-access full text
Quick overview. Review the resource’s basic details, then access the content using the main button. This page shows only the information needed to identify, cite, and open the work.

Resource access

Open the content from the main option or choose another available source.

DOAJ DOAJ Articles
Entrar por DOAJ
Main access

Open-access full text

Texto completo identificado como acceso abierto.
Open text
Otras opciones de acceso Elegí el proveedor disponible para esta ficha.
DOAJ CSV Export DOAJ - Open Access Journals
Acceder por DOAJ CSV Export
Importación CSV DOAJ - Open Access Journals
Acceder por Importación CSV
DOAJ OAI-PMH DOAJ Articles
Acceder por DOAJ OAI-PMH

Other available options

When the resource is available on more than one platform, you can choose where to open it.

DOAJ CSV Export DOAJ - Open Access Journals Access available
Open
Importación CSV DOAJ - Open Access Journals Access available
Open
DOAJ OAI-PMH DOAJ Articles Access available
Open

Summary

Descripción general del contenido del recurso.

Insider threats pose a significant and growing risk to organizational cybersecurity, with recent studies indicating a 47% increase in insider incidents from 2018 to 2022. This paper presents a comparative analysis of unsupervised and supervised machine learning approaches for detecting potential insider threats through network traffic anomaly identification. We develop and evaluate an Isolation Forest (unsupervised) and a Random Forest (supervised) model, training them on a simulated dataset representing six months of network logs from a mid-sized company. Our study introduces a unique feature set combining traditional network metrics with temporal and behavioral indicators, enhancing the models' detection capabilities. Results show that the Random Forest classifier outperforms the Isolation Forest, with F1-scores of 0.6425 and 0.4624, respectively. However, the unsupervised approach shows promise in scenarios lacking labeled data. Key findings reveal that increased connection frequency and data transfer volume are critical indicators of potential threats, with temporal patterns also playing a significant role. This study provides valuable insights into the strengths and limitations of each approach, offering practical implications for real-world digital forensics investigations. We contribute to the field by proposing a hybrid approach that leverages the strengths of both methods, potentially improving the accuracy and adaptability of insider threat detection systems. These findings pave the way for more robust, context-aware cybersecurity measures in the digital age.

How to cite

Elegí el formato que necesitás y copiá la referencia al portapapeles.

APA 7

al, S. P. E. (2025). Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches. https://doi.org/10.33093/jiwe.2025.4.2.10

MLA

al, Sellappan Palaniappan et. "Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches." 2025. https://doi.org/10.33093/jiwe.2025.4.2.10.

Chicago

al, Sellappan Palaniappan et. 2025. "Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches.". https://doi.org/10.33093/jiwe.2025.4.2.10.

Harvard

al, S. P. E. 2025, Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches, MMU Press, available at: https://doi.org/10.33093/jiwe.2025.4.2.10 [Accessed 7 Aug. 2026].

Share and print

Save the record, copy its permanent link, or print it as a PDF.

Export reference

You can export the record in common formats for use in a reference manager.

Resource details

Bibliographic information to help confirm that this is the correct material.

Title
Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches
Author / contributors
Sellappan Palaniappan et al
Publisher
MMU Press
Publication year
2025
ISSN
2821-370X
ISSN
2821-370X
Language
English

Subjects

Explore related resources through these subjects.

Copied