A Proactive Insider Threat Management Framework Using Explainable Machine Learning
Selma Shikonde, Mike Wa Nkongolo

TL;DR
This paper introduces the IT-XML framework that combines explainable machine learning and process models to proactively identify and mitigate insider threats in organizations, enhancing security decision-making.
Contribution
It presents a novel framework integrating CRISP-DM, HMM, and explainability techniques for proactive insider threat management using survey data and pattern recognition.
Findings
Classified organizations at developing security maturity with 97-98% confidence
Achieved 91.7% classification accuracy in threat pattern recognition
Identified audit log access limits as critical controls for insider threat mitigation
Abstract
Over the years, the technological landscape has evolved, reshaping the security posture of organisations and increasing their exposure to cybersecurity threats, many originating from within. Insider threats remain a major challenge, particularly in sectors where cybersecurity infrastructure, expertise, and regulations are still developing. This study proposes the Insider Threat Explainable Machine Learning (IT-XML) framework, which integrates the Cross-Industry Standard Process for Data Mining (CRISP-DM) with Hidden Markov Models (HMM) to enhance proactive insider threat management and decision-making. A quantitative approach is adopted using an online questionnaire to assess employees' knowledge of insider threat patterns, access control, privacy practices, and existing policies across three large data-sensitive organisations. The IT-XML framework provides assessment capabilities…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Software System Performance and Reliability · Network Security and Intrusion Detection
