NORMA eResearch @NCI Library

Understanding the influence of behaviour monitoring tools towards mitigating insider threats in hybrid working environments through behavioural analytics

Murimuri, Sravan Kumar (2025) Understanding the influence of behaviour monitoring tools towards mitigating insider threats in hybrid working environments through behavioural analytics. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (2MB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (480kB) | Preview

Abstract

Hybrid working arrangements would pose a major challenge to the insider threat detection tools since the traditional monitoring tools are not very effective in detecting malicious activities in work environments that are dispersed. In 2023, organisations have suffered severe consequences due to insider threats, 45% led to data loss and 43% to brand damage, but less than one third of the organisations perceived that they were well prepared to counter threats. The study aimed to assess the efficiency of machine learning models (Random Forest, Stacking Classifier, and XGBoost) enhanced by behavioural analytics to detect insider threats and compare their results in relation to improving the model of child enhancement accuracy and reducing false positives in the hybrid workplaces. The research employed a positivist philosophy and the deductive approach based on the Kaggle Insider Threat dataset. Preprocessing of data involved the management of missing data, outliers, class balancing using SMOTE, and multicollinearity filtering. The accuracy, precision, recall, F1-score, and AUC were used to measure, train, and evaluate three ensemble models. XGBoost was the most suitable model, with 99.20% accuracy, 100% recall, and 98.57% F1-score, followed by Random Forest (99.07% accuracy, 97.58% F1-score) and Stacking Classifier (98.67% accuracy, 97.58% F1-score). The results show that the use of ML to enhance behavioural monitoring performs well in detecting insider threats in the hybrid environment, as it is more effective than the available methods reported in the literature, and provides support to the use of ensemble methodologies in organisational cybersecurity resilience.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Salahuddin, Jawad
UNSPECIFIED
Subjects: Q Science > QA Mathematics > Electronic computers. Computer science
T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science
Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
H Social Sciences > HD Industries. Land use. Labor > Issues of Labour and Work > Hours of Labour > Flexible work arrangements
Divisions: School of Computing > Master of Science in Cyber Security
Depositing User: Ciara O'Brien
Date Deposited: 03 Sep 2026 11:56
Last Modified: 03 Sep 2026 11:56
URI: https://norma.ncirl.ie/id/eprint/9810

Actions (login required)

View Item View Item