The insider threat is still among the most difficult cybersecurity risks because of the access and capabilities of insiders to hide malicious or careless actions in the ordinary operations. The rules-based system, statistical anomaly detection and traditional machine learning tools are not always efficient in identifying the relational and contextual dependence in an enterprise setting which limits predictive capability as well as high false-positive. This paper presents a graph-baseds model of active preemptive insider threat detection. The Insider Threat Dataset of Multi-source behavioral logs of Classified Environments are converted to a heterogeneous interaction graph, where the nodes represent users, devices, and resources, and the edges indicate the frequency of interaction, sensitivity, and time patterns. Normative measures such as degree, between, eigenvector centrality, community membership, motif patterns and PageRank are derived to display aberrant relational activity. Empirical analysis has shown that a higher number of off-hours of printing/burning, larger volumes of data being exfiltrated, longer occupancy duration, and high-risk travel occur in malicious insiders occupying more influential network positions (much higher PageRank). The full prediction accuracy (FNNs classify every sample correctly) of Graph Neural Networks (GNNs) is high (F1 = 1.0, AUC = 1.0), which is significantly higher than that of the traditional baselines (Random Forest: F1 = 0.7576; XGBoost: F1 = 0.6753). The findings demonstrate the effectiveness of the graph-based methods in providing high-quality behavioral dependencies, with better accuracy and fewer false alarms and greater explainability in real-life insider risk monitoring.
Muhammad Irshad, M. Shafiq, M. Sajjad· American Journal of Data Sci...· 0 citations
The expansion and emergence of multi-tenant cloud platforms have posed significant challenges for securing and maintaining reliable access control, especially when considering how users behave at different times and how cyber threats are constantly evolving. Role-based access control and attribute-based access (ABAC) are examples of traditional access control models that fail to be flexible enough to identify and block unauthorized activities and cross-tenant attacks in current cloud settings. To address these limitations, this study suggests a Secure Behavioral Zero-Trust Access Control Framework (SB-ZTAC), which establishes the integration of 3 modules in one unified framework: Machine learning based behavioral analytics, Zero-trust policy enforcement, and Blockchain based auditing. While the framework uses a behavioural- anomaly detection to produce risk-based access decisions, a zero-trust mechanism dynamically applies access policies according to pre-defined thresholds. Furthermore, a blockchain-based audit layer provides secure and tamper-proof access capability events. Multiple real-world cybersecurity datasets, such as the LANL authentication dataset, UNSW-NB15 and CICIDS2017, are utilized to assess the effectiveness of the proposed framework. Experimental results clearly show that the proposed XGBoost can achieve good detection performance with F1-scores near to 98.0% on LANL and 95.5% on UNSW-NB15 and up to 99.9% on CICIDS2017 data set, while its inference latency is low, typically from 0.002–0.005 ms per sample. In addition, there is minimal computation overhead of the audit logging, making it a real-time solution. The proposed approach provides a scalable and practical solution to improve tenant isolation, improve access control and develop trust in cloud environments by providing multi-tenancy security.
Musab Umair Malik, Muhammad Faisal Shafiq, Muhammad Naveed Sajjad et al.· International Journal of Adv...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.