A METHOD FOR TEMPORAL EARLY FORECASTING OF INSIDER INCIDENTS WITH RISK PROBABILITY CALIBRATION

Authors

DOI:

https://doi.org/10.28925/2663-4023.2026.34.1362

Keywords:

insider threats, early forecasting, lead time, probability calibration, communication lines, cybersystems, queueing theory, throughput capacity, average service time, queueing theory, mathematical modeling.

Abstract

This paper proposes a temporal early-warning forecasting method for insider incidents that transitions from binary "incident / non-incident" classification to estimating risk dynamics over time. Time series of behavioural telemetry and sparse open-source intelligence (OSINT) signals are aggregated using a hierarchical Bayesian state-space model, in which the user's latent risk evolves as an autoregressive process and observations from different modalities are incorporated via their respective likelihood functions. The organizational graph structure is accounted for not by homophilic neighbour averaging, but rather through a heterophily-aware "node-versus-neighbourhood" contrast and a structural prior aligned with the empirically established property of insider connections: anomalous edges predominantly connect the malicious insider to benign custodians of sensitive resources. The output of the method is a calibrated posterior probability of an incident occurring within the forecast horizon, while the alarm rule is constructed under a controlled false-alarm budget that requires signal persistence over multiple days. A computational experiment on a temporal dataset parameterized according to the CERT specification (1,000 users, 420 days, five runs) demonstrated that at a fixed load of 0.1 false alarms per user, telemetry alone detects 0.11 of insiders; incorporating OSINT signals raises this metric to 0.62, and the full proposed method reaches 0.66 with nearly half the false-alarm rate; the area under the ROC curve reaches 0.957, while temperature calibration reduces the Brier score from 0.037 to 0.004 and the expected calibration error from 0.158 to 0.002. Adversarial robustness is evaluated separately: concealment and spoofing of the public digital footprint drops detection down to 0.01–0.06, indicating that OSINT-based early warning is fundamentally vulnerable to evasion by the perpetrator, whereas user ranking is partially preserved due to the structural component. It is shown that credible fusion and masked fine-tuning compensate for this degradation only partially and at the expense of sensitivity under clean conditions.

Downloads

Download data is not yet available.

References

Kirichenko, L., Radivilova, T., & Bulakh, V. (2019). Machine learning in classification time series with fractal properties. Data, 4(1), Article 5, 1–13. https://doi.org/10.3390/data4010005

Radivilova, T., Kirichenko, L., Alghawli, A. S., Ilkov, A., Tawalbeh, M., & Zinchenko, P. (2020). The complex method of intrusion detection based on anomaly detection and misuse detection. In 2020 IEEE 11th International Conference on Dependable Systems, Services and Technologies (DESSERT) (pp. 133–137). IEEE. https://doi.org/10.1109/DESSERT50317.2020.9125051

Kirichenko, L., Pichugina, O., Radivilova, T., & Pavlenko, K. (2023). Application of wavelet transform for machine learning classification of time series. In S. Babichev & V. Lytvynenko (Eds.), Lecture notes in data engineering, computational intelligence, and decision making. ISDMCI 2022 (Lecture Notes on Data Engineering and Communications Technologies, Vol. 149, pp. 445–458). Springer, Cham. https://doi.org/10.1007/978-3-031-16203-9_31

Пантєлєєв, В., Радівілова, Т., Добринін, І., Фісенко, Д., Мазепа, А., & Білодід, В. (2025). Аналіз методів прогнозування внутрішніх загроз на основі аналізу даних соціальної мережі TWITTER. Кібербезпека: освіта, наука, техніка, 4(28), 478–489. https://doi.org/10.28925/2663-4023.2025.28.818

Yuan, S., & Wu, X. (2021). Deep learning for insider threat detection: Review, challenges and opportunities. Computers & Security, 104, Article 102221. https://doi.org/10.1016/j.cose.2021.102221

Daradkeh, Y. I., Kirichenko, L., & Radivilova, T. (2018). Development of QoS methods in the information networks with fractal traffic. International Journal of Electronics and Telecommunications, 64(1), 27–32. https://doi.org/10.24425/118142

Radivilova, T., Kirichenko, L., Panteleev, V., & Mazepa, A. (2024). Analysis of authentication methods for full-stack applications and implementation of a web application with an integrated authentication system. Innovative Technologies and Scientific Solutions for Industries, (3), 76–90. https://doi.org/10.30837/ITSSI.2024.3.076

Nasir, R., Afzal, M., Latif, R., & Iqbal, W. (2021). Behavioral based insider threat detection using deep learning. IEEE Access, 9, 143266–143274. https://doi.org/10.1109/ACCESS.2021.3118297

Al-Mhiqani, M. N., Ahmad, R., Abidin, Z. Z., Abdulkareem, K. H., Mohammed, M. A., Gupta, D., & Shankar, K. (2022). A new intelligent multilayer framework for insider threat detection. Computers & Electrical Engineering, 97, Article 107597. https://doi.org/10.1016/j.compeleceng.2021.107597

Gong, Y., Cui, S., Liu, S., Jiang, B., Dong, C., & Lu, Z. (2024). Graph-based insider threat detection: A survey. Computer Networks, 254, Article 110757. https://doi.org/10.1016/j.comnet.2024.110757

Fei, K., Zhou, J., Su, L., Wang, W., & Chen, Y. (2025). Log2Graph: A graph convolution neural network based method for insider threat detection. Journal of Computer Security, 33(2). https://doi.org/10.3233/JCS-230092

Thi, V. D., Duc, T. T., Nguyen, T. V., & Luong, H.-M. P. (2026). Insider threat detection using knowledge graphs and RiskScore-guided graph neural networks. Engineering, Technology & Applied Science Research, 16(2), 33712–33721. https://doi.org/10.48084/etasr.17187

Dwivedi, V. P., & Bresson, X. (2021). A generalization of transformer networks to graphs. arXiv. https://doi.org/10.48550/arXiv.2012.09699

Ying, C., Cai, T., Luo, S., Zheng, S., Ke, G., He, D., Shen, Y., & Liu, T.-Y. (2021). Do transformers really perform badly for graph representation? In Advances in Neural Information Processing Systems (Vol. 34, pp. 28877–28888). Curran Associates, Inc. https://doi.org/10.48550/arXiv.2106.05234

Rampášek, L., Galkin, M., Dwivedi, V. P., Luu, A. T., Wolf, G., & Beaini, D. (2022). Recipe for a general, powerful, scalable graph transformer. In Advances in Neural Information Processing Systems (Vol. 35, pp. 14501–14515). Curran Associates, Inc. https://doi.org/10.48550/arXiv.2205.12454

Xu, F., Wang, N., Wu, H., Wen, X., Zhao, X., & Wan, H. (2024). Revisiting graph-based fraud detection in sight of heterophily and spectrum. In Proceedings of the AAAI Conference on Artificial Intelligence (Vol. 38, No. 8, pp. 9214–9222). AAAI Press. https://doi.org/10.1609/aaai.v38i8.28773

Zhu, J., Yan, Y., Zhao, L., Heimann, M., Akoglu, L., & Koutra, D. (2020). Beyond homophily in graph neural networks: Current limitations and effective designs. In Advances in Neural Information Processing Systems (Vol. 33, pp. 7793–7804). Curran Associates, Inc. https://doi.org/10.48550/arXiv.2006.11468

Chien, E., Peng, J., Li, P., & Milenkovic, O. (2021). Adaptive universal generalized PageRank graph neural network. arXiv. https://doi.org/10.48550/arXiv.2006.07988

Guo, C., Pleiss, G., Sun, Y., & Weinberger, K. Q. (2017). On calibration of modern neural networks. In Proceedings of the 34th International Conference on Machine Learning (ICML) (pp. 1321–1330). PMLR. https://doi.org/10.48550/arXiv.1706.04599

Angelopoulos, A. N., & Bates, S. (2023). Conformal prediction: A gentle introduction. Foundations and Trends in Machine Learning, 16(4), 494–591. https://doi.org/10.1561/2200000101

Gibbs, I., & Candès, E. (2021). Adaptive conformal inference under distribution shift. In Advances in Neural Information Processing Systems (Vol. 34, pp. 1660–1672). Curran Associates, Inc. https://doi.org/10.48550/arXiv.2106.00170

Candès, E., Lei, L., & Ren, Z. (2023). Conformalized survival analysis. Journal of the Royal Statistical Society Series B, 85(1), 24–45. https://doi.org/10.1093/jrsssb/qkac004

Zügner, D., Akbarnejad, A., & Günnemann, S. (2018). Adversarial attacks on neural networks for graph data. In Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining (pp. 2847–2856). ACM. https://doi.org/10.1145/3219819.3220078

Freitas, S., Yang, D., Kumar, S., Tong, H., & Chau, D. H. (2022). Graph vulnerability and robustness: A survey. IEEE Transactions on Knowledge and Data Engineering, 35(6), 5915–5934. https://doi.org/10.1109/TKDE.2022.3163672

Glasser, J., & Lindauer, B. (2013). Bridging the gap: A pragmatic approach to generating insider threat data. In 2013 IEEE Security and Privacy Workshops (pp. 98–104). IEEE. https://doi.org/10.1109/SPW.2013.37

Harilal, A., Toffalini, F., Castellanos, J., Guarnizo, J., Homoliak, I., & Ochoa, M. (2017). TWOS: A dataset of malicious insider threat behavior based on a gamified competition. In Proceedings of the 2017 International Workshop on Managing Insider Security Threats (pp. 45–56). ACM. https://doi.org/10.1145/3139923.3139929

Klimt, B., & Yang, Y. (2004). The Enron corpus: A new dataset for email classification research. In J.-F. Boulicaut, F. Esposito, F. Giannotti, & D. Pedreschi (Eds.), Machine Learning: ECML 2004 (Lecture Notes in Computer Science, Vol. 3201, pp. 217–226). Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-30115-8_22

Downloads


Abstract views: 7

Published

2026-09-24

How to Cite

Radivilova, T., & Pantelieiev, V. (2026). A METHOD FOR TEMPORAL EARLY FORECASTING OF INSIDER INCIDENTS WITH RISK PROBABILITY CALIBRATION. Electronic Professional Scientific Journal «Cybersecurity: Education, Science, Technique», 2(34), 687–701. https://doi.org/10.28925/2663-4023.2026.34.1362