A METHOD FOR TEMPORAL EARLY FORECASTING OF INSIDER INCIDENTS WITH RISK PROBABILITY CALIBRATION
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1362Keywords:
insider threats, early forecasting, lead time, probability calibration, communication lines, cybersystems, queueing theory, throughput capacity, average service time, queueing theory, mathematical modeling.Abstract
This paper proposes a temporal early-warning forecasting method for insider incidents that transitions from binary "incident / non-incident" classification to estimating risk dynamics over time. Time series of behavioural telemetry and sparse open-source intelligence (OSINT) signals are aggregated using a hierarchical Bayesian state-space model, in which the user's latent risk evolves as an autoregressive process and observations from different modalities are incorporated via their respective likelihood functions. The organizational graph structure is accounted for not by homophilic neighbour averaging, but rather through a heterophily-aware "node-versus-neighbourhood" contrast and a structural prior aligned with the empirically established property of insider connections: anomalous edges predominantly connect the malicious insider to benign custodians of sensitive resources. The output of the method is a calibrated posterior probability of an incident occurring within the forecast horizon, while the alarm rule is constructed under a controlled false-alarm budget that requires signal persistence over multiple days. A computational experiment on a temporal dataset parameterized according to the CERT specification (1,000 users, 420 days, five runs) demonstrated that at a fixed load of 0.1 false alarms per user, telemetry alone detects 0.11 of insiders; incorporating OSINT signals raises this metric to 0.62, and the full proposed method reaches 0.66 with nearly half the false-alarm rate; the area under the ROC curve reaches 0.957, while temperature calibration reduces the Brier score from 0.037 to 0.004 and the expected calibration error from 0.158 to 0.002. Adversarial robustness is evaluated separately: concealment and spoofing of the public digital footprint drops detection down to 0.01–0.06, indicating that OSINT-based early warning is fundamentally vulnerable to evasion by the perpetrator, whereas user ranking is partially preserved due to the structural component. It is shown that credible fusion and masked fine-tuning compensate for this degradation only partially and at the expense of sensitivity under clean conditions.
Downloads
References
Kirichenko, L., Radivilova, T., & Bulakh, V. (2019). Machine learning in classification time series with fractal properties. Data, 4(1), Article 5, 1–13. https://doi.org/10.3390/data4010005
Radivilova, T., Kirichenko, L., Alghawli, A. S., Ilkov, A., Tawalbeh, M., & Zinchenko, P. (2020). The complex method of intrusion detection based on anomaly detection and misuse detection. In 2020 IEEE 11th International Conference on Dependable Systems, Services and Technologies (DESSERT) (pp. 133–137). IEEE. https://doi.org/10.1109/DESSERT50317.2020.9125051
Kirichenko, L., Pichugina, O., Radivilova, T., & Pavlenko, K. (2023). Application of wavelet transform for machine learning classification of time series. In S. Babichev & V. Lytvynenko (Eds.), Lecture notes in data engineering, computational intelligence, and decision making. ISDMCI 2022 (Lecture Notes on Data Engineering and Communications Technologies, Vol. 149, pp. 445–458). Springer, Cham. https://doi.org/10.1007/978-3-031-16203-9_31
Пантєлєєв, В., Радівілова, Т., Добринін, І., Фісенко, Д., Мазепа, А., & Білодід, В. (2025). Аналіз методів прогнозування внутрішніх загроз на основі аналізу даних соціальної мережі TWITTER. Кібербезпека: освіта, наука, техніка, 4(28), 478–489. https://doi.org/10.28925/2663-4023.2025.28.818
Yuan, S., & Wu, X. (2021). Deep learning for insider threat detection: Review, challenges and opportunities. Computers & Security, 104, Article 102221. https://doi.org/10.1016/j.cose.2021.102221
Daradkeh, Y. I., Kirichenko, L., & Radivilova, T. (2018). Development of QoS methods in the information networks with fractal traffic. International Journal of Electronics and Telecommunications, 64(1), 27–32. https://doi.org/10.24425/118142
Radivilova, T., Kirichenko, L., Panteleev, V., & Mazepa, A. (2024). Analysis of authentication methods for full-stack applications and implementation of a web application with an integrated authentication system. Innovative Technologies and Scientific Solutions for Industries, (3), 76–90. https://doi.org/10.30837/ITSSI.2024.3.076
Nasir, R., Afzal, M., Latif, R., & Iqbal, W. (2021). Behavioral based insider threat detection using deep learning. IEEE Access, 9, 143266–143274. https://doi.org/10.1109/ACCESS.2021.3118297
Al-Mhiqani, M. N., Ahmad, R., Abidin, Z. Z., Abdulkareem, K. H., Mohammed, M. A., Gupta, D., & Shankar, K. (2022). A new intelligent multilayer framework for insider threat detection. Computers & Electrical Engineering, 97, Article 107597. https://doi.org/10.1016/j.compeleceng.2021.107597
Gong, Y., Cui, S., Liu, S., Jiang, B., Dong, C., & Lu, Z. (2024). Graph-based insider threat detection: A survey. Computer Networks, 254, Article 110757. https://doi.org/10.1016/j.comnet.2024.110757
Fei, K., Zhou, J., Su, L., Wang, W., & Chen, Y. (2025). Log2Graph: A graph convolution neural network based method for insider threat detection. Journal of Computer Security, 33(2). https://doi.org/10.3233/JCS-230092
Thi, V. D., Duc, T. T., Nguyen, T. V., & Luong, H.-M. P. (2026). Insider threat detection using knowledge graphs and RiskScore-guided graph neural networks. Engineering, Technology & Applied Science Research, 16(2), 33712–33721. https://doi.org/10.48084/etasr.17187
Dwivedi, V. P., & Bresson, X. (2021). A generalization of transformer networks to graphs. arXiv. https://doi.org/10.48550/arXiv.2012.09699
Ying, C., Cai, T., Luo, S., Zheng, S., Ke, G., He, D., Shen, Y., & Liu, T.-Y. (2021). Do transformers really perform badly for graph representation? In Advances in Neural Information Processing Systems (Vol. 34, pp. 28877–28888). Curran Associates, Inc. https://doi.org/10.48550/arXiv.2106.05234
Rampášek, L., Galkin, M., Dwivedi, V. P., Luu, A. T., Wolf, G., & Beaini, D. (2022). Recipe for a general, powerful, scalable graph transformer. In Advances in Neural Information Processing Systems (Vol. 35, pp. 14501–14515). Curran Associates, Inc. https://doi.org/10.48550/arXiv.2205.12454
Xu, F., Wang, N., Wu, H., Wen, X., Zhao, X., & Wan, H. (2024). Revisiting graph-based fraud detection in sight of heterophily and spectrum. In Proceedings of the AAAI Conference on Artificial Intelligence (Vol. 38, No. 8, pp. 9214–9222). AAAI Press. https://doi.org/10.1609/aaai.v38i8.28773
Zhu, J., Yan, Y., Zhao, L., Heimann, M., Akoglu, L., & Koutra, D. (2020). Beyond homophily in graph neural networks: Current limitations and effective designs. In Advances in Neural Information Processing Systems (Vol. 33, pp. 7793–7804). Curran Associates, Inc. https://doi.org/10.48550/arXiv.2006.11468
Chien, E., Peng, J., Li, P., & Milenkovic, O. (2021). Adaptive universal generalized PageRank graph neural network. arXiv. https://doi.org/10.48550/arXiv.2006.07988
Guo, C., Pleiss, G., Sun, Y., & Weinberger, K. Q. (2017). On calibration of modern neural networks. In Proceedings of the 34th International Conference on Machine Learning (ICML) (pp. 1321–1330). PMLR. https://doi.org/10.48550/arXiv.1706.04599
Angelopoulos, A. N., & Bates, S. (2023). Conformal prediction: A gentle introduction. Foundations and Trends in Machine Learning, 16(4), 494–591. https://doi.org/10.1561/2200000101
Gibbs, I., & Candès, E. (2021). Adaptive conformal inference under distribution shift. In Advances in Neural Information Processing Systems (Vol. 34, pp. 1660–1672). Curran Associates, Inc. https://doi.org/10.48550/arXiv.2106.00170
Candès, E., Lei, L., & Ren, Z. (2023). Conformalized survival analysis. Journal of the Royal Statistical Society Series B, 85(1), 24–45. https://doi.org/10.1093/jrsssb/qkac004
Zügner, D., Akbarnejad, A., & Günnemann, S. (2018). Adversarial attacks on neural networks for graph data. In Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining (pp. 2847–2856). ACM. https://doi.org/10.1145/3219819.3220078
Freitas, S., Yang, D., Kumar, S., Tong, H., & Chau, D. H. (2022). Graph vulnerability and robustness: A survey. IEEE Transactions on Knowledge and Data Engineering, 35(6), 5915–5934. https://doi.org/10.1109/TKDE.2022.3163672
Glasser, J., & Lindauer, B. (2013). Bridging the gap: A pragmatic approach to generating insider threat data. In 2013 IEEE Security and Privacy Workshops (pp. 98–104). IEEE. https://doi.org/10.1109/SPW.2013.37
Harilal, A., Toffalini, F., Castellanos, J., Guarnizo, J., Homoliak, I., & Ochoa, M. (2017). TWOS: A dataset of malicious insider threat behavior based on a gamified competition. In Proceedings of the 2017 International Workshop on Managing Insider Security Threats (pp. 45–56). ACM. https://doi.org/10.1145/3139923.3139929
Klimt, B., & Yang, Y. (2004). The Enron corpus: A new dataset for email classification research. In J.-F. Boulicaut, F. Esposito, F. Giannotti, & D. Pedreschi (Eds.), Machine Learning: ECML 2004 (Lecture Notes in Computer Science, Vol. 3201, pp. 217–226). Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-30115-8_22
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Тамара Радівілова, Вадим Пантєлєєв

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.