Skip to content
Open access

ITDF: A Deep Learning Insider Threat Detection Framework Based on Abnormal Logon Behavior

2026 · IEEE Access · Vol 14, pp. 141753-141772 · 0 citations · 51 references

Abstract

Insider threats remain one of the most difficult issues in cybersecurity because a malicious insider can misuse legitimate credentials to compromise critical assets. Existing detection approaches predominantly focus on post-authentication activities, limiting their ability to prevent damage early. This work proposes a proactive pre-access detection layer that can be incorporated with contemporary insider threat detection systems. This layer serves as an early warning subsystem that identifies suspicious logon events before the user accesses critical files, systems, or assets. The framework integrates heterogeneous data sources from the CERT r4.2 dataset, including logon records, psychometric profiles, and organizational attributes. Given the extreme class imbalance inherent in insider threat datasets, this study explicitly investigates multiple strategies for addressing class imbalance, including resampling and cost-sensitive learning using Focal Loss as the optimization strategy. We evaluate four widely used ML and DL models within the proposed ITDF under three configurations: ITDF-B (baseline), ITDF-R (resampled), and ITDF-CS (Cost-Sensitive). Results show that the LSTM model combined with Focal Loss (ITDF-CS) outperforms both its ITDF-B and ITDF-R counterparts, as well as other models, achieving a precision of 0.85, a recall of 0.91, and an F1-score of 0.88. These findings highlight the effectiveness of leveraging temporal logon patterns, combined with cost-sensitive optimization, to identify potentially malicious authentication activity before access to sensitive organizational resources.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.