[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-128278-en":3,"doc-seo-128278-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},128278,962085570644,"Evangeline","https://ap-avatar.wpscdn.com/davatar_994ba38a5ba835b3df7d355c54d3ed8d",8,"Research & Report","Anomaly Detection in Network Traffic for Insider Threat Identification - A Comparative Study of Unsupervised and Supervised Machine Learning Approaches","Insider threats pose a growing risk to organizational cybersecurity, driving increased attention to machine learning-based detection from network traffic. This study compares unsupervised and supervised approaches by building and evaluating an Isolation Forest and a Random Forest model on a simulated dataset covering six months of network logs. A hybrid feature set combines network metrics with temporal and behavioral indicators. Results show Random Forest outperforms Isolation Forest in F1-scores, while unsupervised learning remains promising when labeled data is unavailable.","Journal of Informatics and Web Engineering  \nVol. 4 No. 2 (June 2025) eISSN: 2821-370X  \nAnomaly Detection in Network Traffic for Insider Threat Identification: A Comparative Study of Unsupervised and Supervised Machine  \nLearning Approaches  \nSellappan Palaniappan1*, Rajasvaran Logeswaran2, Shapla Khanam3  \n1Corporate Office, HELP University, No. 15, Jalan Sri Semantan 1, Off Jalan Semantan, Bukit Damansara 50490 Kuala Lumpur, Malaysia  \n2,3Faculty of Computing and Digital Technology, HELP University, Persiaran Cakerawala, Subang Bestari, 40150 Shah Alam, Selangor, Malaysia  \n*corresponding author: ([sellappan.p@help.edu.my](sellappan.p@help.edu.my); ORCiD: 0009-0009-1168-2864)  \nAbstract-Insider threats pose a significant and growing risk to organizational cybersecurity, with recent studies indicating a 47% increase in insider incidents from 2018 to 2022. This paper presents a comparative analysis of unsupervised and supervised machine learning approaches for detecting potential insider threats through network traffic anomaly identification. We develop and evaluate an Isolation Forest (unsupervised) and a Random Forest (supervised) model, training them on a simulated dataset representing six months of network logs from a mid-sized company. Our study introduces a unique feature set combining traditional network metrics with temporal and behavioural indicators, enhancing the models' detection capabilities. Results show that the Random Forest classifier outperforms the Isolation Forest, with F1-scores of 0.6425 and 0.4624, respectively. However, the unsupervised approach shows promise in scenarios lacking labelled data. Key findings reveal that increased connection frequency and data transfer volume are critical indicators of potential threats, with temporal patterns also playing a significant role. This study provides valuable insights into the strengths and limitations of each approach, offering practical implications for real-world digital forensics investigations. We contribute to the field by proposing a hybrid approach that leverages the strengths of both methods, potentially improving the accuracy and adaptability of insider threat detection systems. These findings pave the way for more robust, contextaware cybersecurity measures in the digital age.  \nKeywords—Insider Threat Detection, Network Security, Machine Learning, Anomaly Detection, Digital Forensics  \nReceived:29 August 2024; Accepted: 28 December 2024; Published: 16 June 2025 This is an open access article under the CC BY-NC-ND 4.0 license.  \n1. INTRODUCTION  \nCybersecurity threats come from both within and without organizations. Unlike external attacks, insider threats originate from within the organization's network, and this makes threat detection more challenging because they have legal access to corporate resources. According to the 2023 Insider Threat Report by Cybersecurity Insiders, 74% of organizations feel vulnerable to insider threats, with 39% reporting an increase in insider incidents over the past 12  \nmonths [1] . This alarming trend underscores the growing importance of developing effective insider threat detection mechanisms.  \nConventional or traditional rule-based detection systems do not always detect insider threats as insiders are typically authorized users who have access to their organization's resources. Such systems are weak in differentiating between normal and malicious behavioural patterns when insiders use their own legitimate access privileges to conduct malicious activities. Recent studies in [2-5] highlight the effectiveness of using advanced machine learning techniques in cybersecurity applications, including for intrusion detection and malware classification. The adaptability and pattern recognition capabilities of machine learning algorithms allow them to identify the subtle anomalies in insider threats.  \nThe process of detecting and mitigating insider threats is costly, in terms of financial resources as well as the potentia","cbCaicxZXwjU0qdH","https://ap.wps.com/l/cbCaicxZXwjU0qdH","pdf",676021,2,1,13,"English","en",105,"# Introduction\n## Background and challenge of insider threat detection\n## Limitations of rule-based systems and motivation for ML\n## Cost impact and need for effective methods\n# Research Questions and Objectives\n## Research questions\n## Research objectives","[{\"question\":\"What machine learning approaches are compared for insider threat detection?\",\"answer\":\"The study compares an unsupervised Isolation Forest model with a supervised Random Forest model using simulated network-log data.\"},{\"question\":\"How is the dataset designed for evaluating the models?\",\"answer\":\"The models are trained and evaluated on a simulated dataset representing six months of network traffic, including insider threat scenarios.\"},{\"question\":\"Which model performs better and under what data condition?\",\"answer\":\"Random Forest achieves higher F1-scores than Isolation Forest, while Isolation Forest remains promising when labeled data is not available.\"}]","Anomaly Detection in Network Traffic for Insider Threat Identification - A Comparative Study of Unsupervised and Supervised Machine Learning Approaches | PDF",1785946501,33,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"anomaly-detection-in-network-traffic-for-insider-threat-identification-a-comparative-study-of-unsupervised-and-supervised-machine-learning-approaches","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,48,51],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":20},"https://docshare.wps.com/document/","Document",{"item":49,"name":12,"@type":44,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":44,"position":53},"https://docshare.wps.com/document/anomaly-detection-in-network-traffic-for-insider-threat-identification-a-comparative-study-of-unsupervised-and-supervised-machine-learning-approaches/128278/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-27","2026-08-05",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What machine learning approaches are compared for insider threat detection?","Question",{"text":76,"@type":77},"The study compares an unsupervised Isolation Forest model with a supervised Random Forest model using simulated network-log data.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How is the dataset designed for evaluating the models?",{"text":81,"@type":77},"The models are trained and evaluated on a simulated dataset representing six months of network traffic, including insider threat scenarios.",{"name":83,"@type":74,"acceptedAnswer":84},"Which model performs better and under what data condition?",{"text":85,"@type":77},"Random Forest achieves higher F1-scores than Isolation Forest, while Isolation Forest remains promising when labeled data is not available.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":47,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]