Torna ai risultati
Scheda bibliografica · Consultazione e accesso
Artículo

Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches

Sellappan Palaniappan et al · MMU Press · 2025

Testo completo ad accesso aperto
Lettura rapida. Controlla i dati essenziali della risorsa e accedi al contenuto con il pulsante principale. La scheda mostra solo le informazioni necessarie per identificare, citare e aprire l’opera.

Accesso alla risorsa

Apri il contenuto dall’opzione principale o scegli un’altra fonte disponibile.

DOAJ DOAJ Articles
Entrar por DOAJ
Accesso principale

Testo completo ad accesso aperto

Texto completo identificado como acceso abierto.
Apri testo
Otras opciones de acceso Elegí el proveedor disponible para esta ficha.
DOAJ CSV Export DOAJ - Open Access Journals
Acceder por DOAJ CSV Export
Importación CSV DOAJ - Open Access Journals
Acceder por Importación CSV
DOAJ OAI-PMH DOAJ Articles
Acceder por DOAJ OAI-PMH

Altre opzioni disponibili

Se la risorsa è presente su più piattaforme, puoi scegliere dove aprirla.

DOAJ CSV Export DOAJ - Open Access Journals Accesso disponibile
Apri
Importación CSV DOAJ - Open Access Journals Accesso disponibile
Apri
DOAJ OAI-PMH DOAJ Articles Accesso disponibile
Apri

Riepilogo

Descripción general del contenido del recurso.

Insider threats pose a significant and growing risk to organizational cybersecurity, with recent studies indicating a 47% increase in insider incidents from 2018 to 2022. This paper presents a comparative analysis of unsupervised and supervised machine learning approaches for detecting potential insider threats through network traffic anomaly identification. We develop and evaluate an Isolation Forest (unsupervised) and a Random Forest (supervised) model, training them on a simulated dataset representing six months of network logs from a mid-sized company. Our study introduces a unique feature set combining traditional network metrics with temporal and behavioral indicators, enhancing the models' detection capabilities. Results show that the Random Forest classifier outperforms the Isolation Forest, with F1-scores of 0.6425 and 0.4624, respectively. However, the unsupervised approach shows promise in scenarios lacking labeled data. Key findings reveal that increased connection frequency and data transfer volume are critical indicators of potential threats, with temporal patterns also playing a significant role. This study provides valuable insights into the strengths and limitations of each approach, offering practical implications for real-world digital forensics investigations. We contribute to the field by proposing a hybrid approach that leverages the strengths of both methods, potentially improving the accuracy and adaptability of insider threat detection systems. These findings pave the way for more robust, context-aware cybersecurity measures in the digital age.

Come citare

Elegí el formato que necesitás y copiá la referencia al portapapeles.

APA 7

al, S. P. E. (2025). Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches. https://doi.org/10.33093/jiwe.2025.4.2.10

MLA

al, Sellappan Palaniappan et. "Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches." 2025. https://doi.org/10.33093/jiwe.2025.4.2.10.

Chicago

al, Sellappan Palaniappan et. 2025. "Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches.". https://doi.org/10.33093/jiwe.2025.4.2.10.

Harvard

al, S. P. E. 2025, Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches, MMU Press, available at: https://doi.org/10.33093/jiwe.2025.4.2.10 [Accessed 7 Aug. 2026].

Condividi e stampa

Salva la scheda, copia il link permanente o stampala in PDF.

Esporta riferimento

Esporta il record nei formati più comuni per usarlo con un gestore bibliografico.

Dettagli della risorsa

Informazioni bibliografiche utili per verificare che sia il materiale corretto.

Titolo
Anomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine Learning Approaches
Autore / collaboratori
Sellappan Palaniappan et al
Editore
MMU Press
Anno di pubblicazione
2025
ISSN
2821-370X
ISSN
2821-370X
Lingua
Inglés

Soggetti

Esplora risorse correlate a partire da questi soggetti.

Copiato