Skip to main navigation Skip to search Skip to main content

Enhancing User Behavior Analytics for Insider Threat Detection Through Hierarchical Organizational Context

  • Souhad Ebrahim

Student thesis: Master's Dissertation

Abstract

Insider threat detection remains a difficult problem because malicious activity is often carried out by users with legitimate access to organizational systems and data. Although machine learning has improved the detection of anomalous behavior, many existing approaches still perform poorly in real Security Operations Center (SOC) environments because they rely on broad baselines, generate excessive false positives, and make limited use of organizational context. These limitations reduce their practical value in highly imbalanced settings, where analysts must work under constrained alert budgets. This thesis presents a machine-learning-based context-aware anomaly detection approach for insider threat detection that combines behavioral features with hierarchical organizational context, represented as spatial Zscore features, and fuses them with temporal indicators and a control baseline to better separate genuinely suspicious behavior from normal variations in work patterns.The proposed approach was evaluated under highly imbalanced conditions to reflect a real-world scenario and a realistic operational environment. The results show that integrating hierarchical context improves the overall performance over context-blind baselines across all single-view configurations, achieving the strongest results: Precision of 0.9101, recall of 0.9518, F1-score of 0.9305, and PR-AUC of 0.9801. The findings also reveal that individual organizational layers possess distinct, scenario-driven detection capabilities that complement one another within the fusion architecture. Overall, the thesis shows that anomaly detection becomes more effective and practical when behavioral modeling is enhanced with hierarchical organizational context and interpreted to provide a clearer link between machine learning outputs and real-world insider threat investigations, thereby supporting SOC decision-making.
Date of Award2026
Original languageAmerican English
Awarding Institution
  • HBKU College of Science and Engineering

Keywords

  • anomaly detection
  • cybersecurity
  • insider threat detection
  • machine learning
  • SOC
  • user behavior analytics

Cite this

'