Facebook pixel tracking

The Science and Information (SAI) Organization publishes open-access peer-reviewed journals in computer science and artificial intelligence.

Contact Info
Website thesai.org
Follow Us
Contact Info
Follow Us
Research Article | Open Access |

User Behaviour Analysis for Insider Threat Detection Using Machine Learning: A Case Study in Enterprise Web Application Security

Author 1: Yosep Author 2: Aditya Kurniawan
International Journal of Advanced Computer Science and Applications (IJACSA) · Vol. 17, No. 3 · Published 2026

DOI: https://doi.org/10.14569/IJACSA.2026.0170310

Abstract

This study presents a user behaviour analysis approach for detecting insider threats in an enterprise web application environment. The approach applies machine learning techniques to analyze patterns of user activity. Using a primary dataset collected from a leading ICT distributor company in Indonesia with nationwide channel operations over January–June 2025, we identify patterns of normal and anomalous user activities indicative of insider threats. Three machine learning models were implemented: Random Forest, Support Vector Machine (SVM) with RBF kernel, and 1D CNN, which are widely used in insider-threat and anomaly-detection research. Severe class imbalance was mitigated via undersampling followed by SMOTE. Random Forest delivered the best performance on the test set (Accuracy 97.38%, F1-Score 97.77%, ROC-AUC 99.82%), with CNN and SVM also showing strong anomaly sensitivity. The findings demonstrate a practical, high-accuracy insider-threat detector trained on real enterprise logs, not simulated datasets, suitable for deployment in Indonesian enterprise settings.

Keywords

How to Cite this Article

Yosep, & Kurniawan, A. (2026). User Behaviour Analysis for Insider Threat Detection Using Machine Learning: A Case Study in Enterprise Web Application Security. International Journal of Advanced Computer Science and Applications, 17(3). https://doi.org/10.14569/IJACSA.2026.0170310

Yosep, and Aditya Kurniawan. "User Behaviour Analysis for Insider Threat Detection Using Machine Learning: A Case Study in Enterprise Web Application Security." International Journal of Advanced Computer Science and Applications, vol. 17, no. 3, 2026, https://doi.org/10.14569/IJACSA.2026.0170310.

@article{Yosep2026,
  title     = {User Behaviour Analysis for Insider Threat Detection Using Machine Learning: A Case Study in Enterprise Web Application Security},
  journal   = {International Journal of Advanced Computer Science and Applications},
  volume    = {17},
  number    = {3},
  year      = {2026},
  publisher = {The Science and Information Organization},
  author    = {Yosep and Aditya Kurniawan},
  doi       = {10.14569/IJACSA.2026.0170310},
  url       = {https://doi.org/10.14569/IJACSA.2026.0170310}
}

Open Access — licensed under a Creative Commons Attribution 4.0 International License. Unrestricted use, distribution, and reproduction in any medium, even commercially, as long as the original work is properly cited.