An Explainable Hybrid Behavioral Analytics Framework for Insider Threat Detection in Hypervisor-Based Cloud Environments
Résumé
Abstract Insider threats remain one of the most challenging cybersecurity problems in hypervisor-based cloud environments because privileged users can exploit legitimate access to compromise virtual machines, manipulate hypervisor configurations, and exfiltrate sensitive data without triggering conventional security mechanisms. Existing approaches largely focus on enterprise user activities and rarely integrate hypervisor telemetry, behavioral analytics, Explainable Artificial Intelligence (XAI), and automated response into a unified framework. This study designed and developed an Explainable Hybrid Behavioral Analytics Framework for insider threat detection in hypervisor-based cloud environments. The study adopted the Design Science Research Methodology (DSRM) to design, implement, and evaluate the proposed framework. Hypervisor telemetry, virtual machine lifecycle events, privileged user activities, and behavioral logs were processed using User and Entity Behavior Analytics (UEBA), while a hybrid artificial intelligence engine integrating Random Forest, XGBoost, Long Short-Term Memory (LSTM), Autoencoder, and Isolation Forest were employed for threat detection. Explainability was achieved using SHAP and LIME, with dynamic risk scoring and automated response supporting real-time mitigation. Experimental evaluation using the CERT Insider Threat, LANL, and TWOS datasets achieved accuracies of 98.70%, 97.90%, and 98.30%, respectively, with F1-scores ranging from 97.35% to 98.25%, false positive rates of 1.20–1.60%, detection latency of 42–55 ms, and explainability scores of 0.91–0.93. The study concludes that integrating hypervisor telemetry, hybrid AI, and XAI provides an accurate, transparent, scalable, and proactive solution for insider threat detection in modern hypervisor-based cloud infrastructures. Keywords: Hypervisor Security, Insider Threat Detection, Explainable Artificial Intelligence (XAI), User and Entity Behavior Analytics (UEBA), Hybrid Artificial Intelligence, Behavioral Analytics, Virtual Machine Introspection (VMI), Hypervisor Telemetry, Cloud Security, Dynamic Risk Scoring
Citer ce document
Accès au document
Texte intégral en lecture en ligne, réservé aux abonnés SPHAERO et aux membres de l'institution. Se connecter
Voir l'article sur le site de la revueStatistiques
Consultations : 1
Téléchargements : 0