Enhancing a Multi-Lens Behavioral Anomaly-Detection Framework for Insider Threat Mitigation
Abstract
The growing challenges posed by insider attacks cannot be addressed by traditional defense mechanisms. This study addresses these challenges by proposing a behavioral anomaly detection framework that examines user activities from four complementary perspectives: aggregate daily actions, temporal event sequences, group sociability patterns, and deviations from data-driven role/peer baselines. The framework employs machine learning models, including Gated Recurrent Unit (GRU) and Long Short-Term Memory (LSTM) predictors, as well as autoencoders, to forecast event sequences and evaluate deviations from data-driven role/peer prototypes learned from historical normal behavior. The prediction mechanism captures static action counts and social interactions and incorporates daily deviation signals through a multilayer perceptron. The resulting decision logic is approximated using an interpretable surrogate decision tree. The framework achieves an overall accuracy of 96.7%, detects 90% of anomalies with a false-positive rate of 2.7%, and provides an early warning lead time of over 3 days before harmful activity manifests. Compared to prior multi-model baselines, the F1 score improves by 5–10 percentage points. Empirical evaluations on the CERT insider threat dataset show that the proposed framework achieves high detection accuracy with low false-positive rates. Results indicate that the average early warning lead time exceeds 3 days before harmful activity occurs. In particular, the fusion model reaches an overall accuracy of about 96.7%, detects roughly 90% of true anomalies at a false positive rate of around 2.7%, and improves the F1 score by approximately 5-10% compared to state-of-the-art baselines. Such results indicate that combining multiple behavioral lenses yields more robust and practically useful alerts than single-view or solely sequence-based methods. This study indicates that a multi-lens deep learning framework can effectively detect insider threats with high accuracy, low false positive rates, and improved interpretability. The proposed methodology provides a practical solution for deployment in organizational security operations.