Insiderwatch AI-Based Insider Threat Detection System
DOI:
https://doi.org/10.47392/IRJAEH.2026.0313Keywords:
Insider Threat Detection, Artificial Intelligence, Machine Learning, Isolation Forest, Anomaly Detection, Cybersecurity, MSMEs, Behavioral Analysis, Risk ScoringAbstract
Insider threats pose a growing risk to Micro, Small, and Medium Enterprises (MSMEs), as traditional cybersecurity solutions primarily focus on external attacks and often fail to detect malicious or risky activities performed by authorized users. INSIDER WATCH is an AI-based insider threat detection system designed to monitor and analyze user behavioral metadata in a privacy-preserving manner. The system employs a hybrid architecture consisting of lightweight endpoint agents and a centralized backend server to collect metadata such as login patterns, file access frequency, application usage, and USB activity. Using unsupervised machine learning techniques, particularly the Isolation Forest algorithm, the system learns normal user behavior patterns and identifies anomalies that may indicate potential insider threats. Detected deviations are assigned risk scores and presented through a user-friendly administrative dashboard that provides real-time alerts and behavioral insights for informed decision-making. By combining AI-driven anomaly detection, affordability, scalability, and privacy-conscious monitoring, INSIDER WATCH offers an effective and practical cybersecurity solution tailored specifically for MSMEs.
Downloads
Downloads
Published
Issue
Section
License
Copyright (c) 2026 International Research Journal on Advanced Engineering Hub (IRJAEH)

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
.