ITDF: A Deep Learning Insider Threat Detection Framework Based on Abnormal Logon Behavior
Abstract
Insider threats remain one of the most difficult issues in cybersecurity because a malicious insider can misuse legitimate credentials to compromise critical assets. Existing detection approaches predominantly focus on post-authentication activities, limiting their ability to prevent damage early. This work proposes a proactive pre-access detection layer that can be incorporated with contemporary insider threat detection systems. This layer serves as an early warning subsystem that identifies suspicious logon events before the user accesses critical files, systems, or assets. The framework integrates heterogeneous data sources from the CERT r4.2 dataset, including logon records, psychometric profiles, and organizational attributes. Given the extreme class imbalance inherent in insider threat datasets, this study explicitly investigates multiple strategies for addressing class imbalance, including resampling and cost-sensitive learning using Focal Loss as the optimization strategy. We evaluate four widely used ML and DL models within the proposed ITDF under three configurations: ITDF-B (baseline), ITDF-R (resampled), and ITDF-CS (Cost-Sensitive). Results show that the LSTM model combined with Focal Loss (ITDF-CS) outperforms both its ITDF-B and ITDF-R counterparts, as well as other models, achieving a precision of 0.85, a recall of 0.91, and an F1-score of 0.88. These findings highlight the effectiveness of leveraging temporal logon patterns, combined with cost-sensitive optimization, to identify potentially malicious authentication activity before access to sensitive organizational resources.