Skip to content
Open access

MLBRS: A Multi-Layer Behavioural Risk Scoring Framework for Insider Threat Detection

2026 · International Conference on Data Technologies and Applications · pp. 874-881 · 0 citations · 19 references
Computer Science

TL;DR

MLRS, a multi-layer behavioural risk scoring framework that combines rule-based scoring, statistical deviation analysis, and Isolation Forest-based anomaly detection to generate continuous employee-level risk scores, is presented.

Abstract

: Insider threats remain difficult to detect because malicious actions often resemble legitimate user behaviour and may evolve gradually over time. This paper presents MLBRS, a multi-layer behavioural risk scoring framework that combines rule-based scoring, statistical deviation analysis, and Isolation Forest-based anomaly detection to generate continuous employee-level risk scores. The framework integrates behavioural indicators, personalised deviation modelling, and multivariate anomaly detection to identify both abrupt and gradual behavioural changes. Due to the limited availability of publicly accessible datasets containing database-query-level insider threat activity, a synthetic dataset was constructed to simulate organisational behaviour with temporal consistency, multiple employee roles, and diverse attack scenarios. Existing insider-threat datasets primarily capture system-level activity and do not adequately represent database interactions. Experimental evaluation demonstrates consistent detection performance, achieving an ROC-AUC of 0.978 and an F1-score of 0.88 on the synthetic dataset. Additional cross-dataset evaluation using CERT-derived behavioural traces shows reduced but stable performance under less aligned behavioural conditions. The results indicate that MLBRS provides an interpretable and scalable approach for behavioural insider threat detection across heterogeneous activity patterns.

Read PDF

Similar papers

Sep 2026

Enhancing a Multi-Lens Behavioral Anomaly-Detection Framework for Insider Threat Mitigation

The growing challenges posed by insider attacks cannot be addressed by traditional defense mechanisms. This study addresses these challenges by proposing a behavioral anomaly detection framework that examines user activities from four complementary perspectives: aggregate daily actions, temporal event sequences, gr...

Ishak Hafdallah, Mousa Farajallah, Sami Alsalamin · 0 citations
Open access Aug 2026

Tri-Level Network Attack Risk Stratification Using IDS-Contextual Ensemble Learning

An Intrusion Detection System (IDS)-contextual ensemble learning framework that assigns network traffic to three operationally meaningful risk tiers: High, Medium and Low is presented.

Reeta Mishra, Neelu Chaudhary · 0 citations
Open access 2026

ITDF: A Deep Learning Insider Threat Detection Framework Based on Abnormal Logon Behavior

Insider threats remain one of the most difficult issues in cybersecurity because a malicious insider can misuse legitimate credentials to compromise critical assets. Existing detection approaches predominantly focus on post-authentication activities, limiting their ability to prevent damage early. This work proposes a...

Laila Hajr, A. Alhogail, Sarah Albassam et al. · 0 citations
Preprint Aug 2026

LLMs for Zero-Shot Threat Detection via Structured Risk Indicators

It is shown that the quality of the generated risk indicators is the main driver of zero-shot cyber threat detection performance, and that retrieval mainly benefits weaker LLMs by generating more discriminative risk indicators, whereas stronger models achieve comparable performance without retrieved context.

A. Al-Ghamdi, S. Layeghy, Marius Portmann · 0 citations
Aug 2026

Multi‐Agent Real‐Time Detection of Insider Threats via Collaborative Reasoning

This work proposes MARS‐ITD (Multi‐Agent Real‐time System for Insider Threat Detection), which consists of a detection framework and an investigation framework that improves real‐time detection performance and interpretability but also provides a scalable, collaborative architecture for LLM‐based security analysis syst...

Kai Cheng, Dong-Kun Li, Weidong Tang et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.