Skip to content
Conference Open access

Playbook Generation for Process Anomalies in Insider Threat Scenarios

2026 · Proceedings of the 23rd International Conference on Security and Cryptography · 0 citations · 29 references

Abstract

: Insider threats represent a big challenge for organizations because insiders have legitimate access and knowledge of organizational processes. Effective defense requires both accurate detection of anomalous behavior and timely response actions. This paper proposes a unified approach that classifies log attributes by their importance for insider threat detection using process mining and an anomaly score to identify process deviations. To address the lack of automated responses, we propose to generate Incident Response (IR) playbooks for business processes using Named Entity Recognition (NER) on insider threat scenarios, combined with Part-of-Speech (POS) tagging and the RE&CT framework, a knowledge base of attack techniques and tactics inspired by MITRE ATT&CK that allows for categorizing IR techniques and actions, to map entities to response actions. The proposed approach is evaluated using coverage, redundancy, usefulness, and efficiency metrics, demonstrating its ability to produce comprehensive and compact response playbooks.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.