[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-122881-en":3,"doc-seo-122881-105":29,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":11,"language":21,"language_code":22,"site_id":23,"html_lang":22,"table_of_contents":24,"faqs":25,"seo_title":26,"seo_description":14,"update_tm":27,"read_time":28},122881,549758252649,"Ivy","https://ap-avatar.wpscdn.com/avatar/8000253669c5317157?_k=1778319167496531819",8,"Research & Report","Employee Watcher - A Machine Learning-based Hybrid Insider Threat Detection Framework - Conference Paper","Insider threats are harmful actions taken by authorized users, creating severe organizational risk. Existing detection approaches often fail to analyze activity-related information in sufficient detail, leading to delayed recognition of malicious intent. To improve this, the paper introduces a hybrid insider threat detection framework that combines machine-learning classification with a statistical layer driven by information-gain metrics. Experiments on CERT r4.2 show 98.94% accuracy, outperforming prior methods, and the framework mitigates bias and data-imbalance issues in real-world settings.","University of Groningen  \nEmployee Watcher  \nRauf, Usman; Wei, Zhiyuan; Mohsen, Fadi  \nPublished in:  \n2023 7th Cyber Security in Networking Conference, CSNet 2023  \nDOI:  \n10.1109/CSNet59123.2023.10339777  \nIMPORTANT NOTE: You are advised to consult the publisher's version (publisher's PDF) if you wish to cite from it. Please check the document version below.  \nDocument Version  \nPublisher's PDF, also known as Version of record  \nPublication date: 2023  \nLink to publication in University of Groningen/UMCG research database  \nCitation for published version (APA):  \nRauf, U. , Wei, Z. , & Mohsen, F. (2023) . Employee Watcher: A Machine Learning-based Hybrid Insider Threat Detection Framework. In 2023 7th Cyber Security in Networking Conference, CSNet 2023 (pp. 39- 45) . (2023 7th Cyber Security in Networking Conference, CSNet 2023) . IEEE.  \n[https://doi.org/10.1109/CSNet59123.2023.10339777](https://doi.org/10.1109/CSNet59123.2023.10339777)  \nCopyright  \nOther than for strictly personal use, it is not permitted to download or to forward/distribute the text or part of it without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license (like Creative Commons) .  \nThe publication may also be distributed here under the terms of Article 25fa of the Dutch Copyright Act, indicated by the “Taverne” license. More information can be found on the University of Groningen website: [https://www.rug.nl/library/open-access/self-archiving-pure/taverne](https://www.rug.nl/library/open-access/self-archiving-pure/taverne)amendment.  \nTake-down policy  \nIf you believe that this document breaches copyright please contact us providing details, and we will remove access to the work immediately and investigate your claim.  \nDownloaded from the University of Groningen/U MCG research database (Pure): [http://www.rug. nl/research/portal. For technical reasons the](http://www.rug. nl/research/portal. For technical reasons the)[ ](http://www.rug. nl/research/portal. For technical reasons the)[number of authors shown on this cover page is limited to 10 maximum.](number of authors shown on this cover page is limited to 10 maximum.)  \nDownload date: 27-12-2024  \n2023 7th Cyber Security in Networking Conference (CSNet) ©2023 IEEE DOI: 10.1109/CSNET59123.2023.10339777| 979-8-3503-4287-1/23/$31.00 |   \nEmployee Watcher: A Machine Learning-based Hybrid Insider Threat Detection Framework  \nUsman Rauf∗ , 1 , Zhiyuan Wei 1 , Fadi Mohsen2  \n1Dept. of Mathematics & Computer Science, Mercy College, NY, USA  \n2 Bernoulli Institute for Mathematics, Computer Science & Artificial Intelligence, University of Groningen, Groningen, Netherlands E-mail: [urauf@mercy.edu](urauf@mercy.edu) ; [zwei1@mercy.edu](zwei1@mercy.edu) ; [f.f.m.mohsen@rug.nl](f.f.m.mohsen@rug.nl)  \n*Corresponding Author  \nAbstract—Insider threats refer to harmful actions carried out by authorized users within an organization, posing the most damaging risks. The increasing number of these threats has revealed the inadequacy of traditional methods for detecting and mitigating insider threats. These existing approaches lack the ability to analyze activity-related information in detail, resulting in delayed detection of malicious intent. To address this, our paper presents a hybrid insider threat detection framework. We enhance prediction accuracy by incorporating a layer of statistical criteria using information gain metrics on top of Machine Learning-based classification. We evaluate the performance of our framework using a real-life threat test dataset (CERT r4.2) and compare it to existing methods on the same dataset [7]. Our initial evaluation demonstrates that our proposed framework achieves an accuracy of 98.94% in detecting insider threats, surpassing the performance of existing methods. Additionally, our framework effectively handles potential bias and data imbalance issues that can arise in real-life scenarios.  \nI. INTRODUCTION  \nIn the past two decade","cbCaimGPdTU53Jel","https://ap.wps.com/l/cbCaimGPdTU53Jel","pdf",554133,1,"English","en",105,"# Abstract\n# Introduction","[{\"question\":\"What problem does the Employee Watcher framework address?\",\"answer\":\"It targets insider threats caused by authorized users and the shortcomings of traditional approaches that detect malicious intent too late.\"},{\"question\":\"How does the framework improve detection performance?\",\"answer\":\"It enhances machine-learning classification with an additional statistical layer using information gain metrics to refine prediction accuracy.\"},{\"question\":\"What dataset and results are reported?\",\"answer\":\"The framework is evaluated on the CERT r4.2 threat test dataset, achieving 98.94% accuracy and outperforming existing methods on the same dataset.\"}]","Employee Watcher - A Machine Learning-based Hybrid Insider Threat Detection Framework - Conference Paper | PDF",1785813487,20,{"code":4,"msg":30,"data":31},"ok",{"site_id":23,"language":22,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":27},"employee-watcher-a-machine-learning-based-hybrid-insider-threat-detection-framework-conference-paper","",{"@graph":35,"@context":84},[36,53,67],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/employee-watcher-a-machine-learning-based-hybrid-insider-threat-detection-framework-conference-paper/122881/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":22,"description":14,"dateModified":61,"datePublished":61,"encodingFormat":60,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":64,"interactionType":65,"userInteractionCount":4},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"What problem does the Employee Watcher framework address?","Question",{"text":74,"@type":75},"It targets insider threats caused by authorized users and the shortcomings of traditional approaches that detect malicious intent too late.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"How does the framework improve detection performance?",{"text":79,"@type":75},"It enhances machine-learning classification with an additional statistical layer using information gain metrics to refine prediction accuracy.",{"name":81,"@type":72,"acceptedAnswer":82},"What dataset and results are reported?",{"text":83,"@type":75},"The framework is evaluated on the CERT r4.2 threat test dataset, achieving 98.94% accuracy and outperforming existing methods on the same dataset.","https://schema.org",{"og:url":51,"og:type":86,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":88,"canonical":51},"index,follow",{"doc_id":7,"site_id":23},{"code":4,"msg":5,"data":91},[92,96,100,104,109,114,119,122,126,129,133],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":45,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":110,"doc_module":4,"doc_module_name":45,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":45,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":28,"slug":125},9,"Religion & Spirituality","religion-spirituality",{"id":28,"doc_module":4,"doc_module_name":45,"category_name":127,"show_sort_weight":28,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":45,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":45,"category_name":135,"show_sort_weight":105,"slug":136},19,"General","general"]