International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1713778

1713778 Vol 1 · Issue 9 Download Paper

Conceptual Model for Insider Threat Classification and Risk Modeling in Complex Digital Systems

Bisola Akeju, Joseph Edivri Jolly I. Ogbole Precious Osobhalenewie Okoruwa Oladapo Fadayomi Toyosi O Abolaji

Subject area: Science,Engineering and Technology  ·  Area of research: Insider Threat Risk Modeling

DOI: 10.64388/IREV1I9-1713778

Abstract

Insider threats remain one of the most persistent and complex challenges in contemporary cybersecurity, particularly within highly interconnected, data-intensive, and adaptive digital environments. Unlike external attacks, insider threats originate from trusted identities with legitimate access, making detection, attribution, and mitigation inherently difficult. This proposes a conceptual model for insider threat classification and risk modeling tailored to complex digital systems, including cloud-native platforms, distributed enterprise architectures, and cyber?physical ecosystems. The model addresses critical limitations of existing approaches, which often rely on static classifications, isolated behavioral indicators, or retrospective analysis, and therefore struggle to capture the dynamic, contextual, and systemic nature of insider risk. The proposed framework integrates two tightly coupled layers: an insider threat classification layer and a dynamic risk modeling layer. The classification layer systematically categorizes insiders based on intent (malicious, negligent, or compromised), capability, access privilege, behavioral patterns, and temporal characteristics, leveraging multi-source data such as activity logs, system context, and behavioral deviations. The risk modeling layer conceptualizes insider risk as a probabilistic and continuously evolving construct, driven by the interaction between insider behavior, asset criticality, system interdependencies, and organizational controls. Advanced modeling approaches, including probabilistic inference, temporal risk scoring, and scenario-based analysis, are incorporated to account for uncertainty, nonlinearity, and cascading effects within complex digital systems. A central contribution of the model lies in its integration mechanism, where classification outcomes dynamically inform risk scores, while evolving risk profiles feedback into reclassification and monitoring priorities. This closed-loop design supports real-time risk awareness, adaptive control strategies, and proactive intervention. Additionally, the model explicitly incorporates governance, ethical, and privacy considerations to ensure responsible deployment within enterprise and critical infrastructure contexts. By providing a unified, system-oriented perspective, the conceptual model advances insider threat research and practice, offering a foundation for resilient security architectures, improved decision-making, and future empirical validation in high-velocity digital environments.

Keywords

Insider Threat, Risk Modeling, Threat Classification, Complex Digital Systems, Cybersecurity Governance, Behavioral Analytics, Enterprise Security

References

[1] Agrafiotis, I., Nurse, J.R., Buckley, O., Legg, P., Creese, S. and Goldsmith, M., 2015. Identifying attack patterns for insider threat detection. Computer Fraud & Security, 2015(7), pp.9-17.

[2] Allen, G. and Derr, R., 2015. Threat assessment and risk analysis: an applied approach. Butterworth-Heinemann.

[3] Anderson, C., Baskerville, R.L. and Kaul, M., 2017. Information security control theory: Achieving a sustainable reconciliation between sharing and protecting the privacy of information. Journal of Management Information Systems, 34(4), pp.1082-1112.

[4] Aven, T., 2016. Risk assessment and risk management: Review of recent advances on their foundation. European journal of operational research, 253(1), pp.1-13.

[5] Awad, M. and Khanna, R., 2015. Efficient learning machines: theories, concepts, and applications for engineers and system designers (p. 268). Springer nature.

[6] Azaria, A., Richardson, A., Kraus, S. and Subrahmanian, V.S., 2015. Behavioral analysis of insider threat: A survey and bootstrapped prediction in imbalanced data. IEEE Transactions on Computational Social Systems, 1(2), pp.135-155.

[7] Barns, S., Cosgrave, E., Acuto, M. and Mcneill, D., 2017. Digital infrastructures and urban governance. Urban Policy and research, 35(1), pp.20-31.

[8] Barocas, S. and Selbst, A.D., 2016. Big data's disparate impact. Calif. L. Rev., 104, p.671.

[9] Blasch, E., Kadar, I., Grewe, L.L., Brooks, R., Yu, W., Kwasinski, A., Thomopoulos, S., Salerno, J. and Qi, H., 2017, May. Panel summary of cyber-physical systems (cps) and internet of things (iot) opportunities with information fusion. In Signal Processing, Sensor/Information Fusion, and Target Recognition XXVI (Vol. 10200, pp. 171-188). SPIE.

[10] Böse, B., Avasarala, B., Tirthapura, S., Chung, Y.Y. and Steiner, D., 2017. Detecting insider threats using radish: A system for real-time anomaly detection in heterogeneous data streams. IEEE Systems Journal, 11(2), pp.471-482.

[11] Buchanan, B., 2016. The cybersecurity dilemma: Hacking, trust, and fear between nations. Oxford University Press.

[12] Büchel, F., Humprecht, E., Castro-Herrero, L., Engesser, S. and Brüggemann, M., 2016. Building empirical typologies with QCA: Toward a classification of media systems. The international journal of press/politics, 21(2), pp.209-232.

[13] Canbek, G., Sagiroglu, S., Temizel, T.T. and Baykal, N., 2017, October. Binary classification performance measures/metrics: A comprehensive visualized roadmap to gain new insights. In 2017 International Conference on Computer Science and Engineering (UBMK) (pp. 821-826). IEEE.

[14] Chen, W.J., Kamath, R., Kelly, A., Lopez, H.H.D., Roberts, M. and Yheng, Y.P., 2015. Systems of insight for digital transformation: Using IBM operational decision manager advanced and predictive analytics. IBM Redbooks.

[15] Costa, D.L., Albrethsen, M.J. and Collins, M.L., 2016. Insider threat indicator ontology (No. CMUSEI2016TR007).

[16] Fabian, B., Ermakova, T. and Junghanns, P., 2015. Collaborative and secure sharing of healthcare data in multi-clouds. Information Systems, 48, pp.132-150.

[17] Farasat, A., Nikolaev, A., Srihari, S.N. and Blair, R.H., 2015. Probabilistic graphical models in modern social network analysis. Social Network Analysis and Mining, 5(1), p.62.

[18] Gray, C.M. and Boling, E., 2016. Inscribing ethics and values in designs for learning: a problematic. Educational technology research and development, 64(5), pp.969-1001.

[19] He, H., Maple, C., Watson, T., Tiwari, A., Mehnen, J., Jin, Y. and Gabrys, B., 2016, July. The security challenges in the IoT enabled cyber-physical systems and opportunities for evolutionary computing & other computational intelligence. In 2016 IEEE congress on evolutionary computation (CEC) (pp. 1015-1021). IEEE.

[20] Heckman, K.E., Stech, F.J., Thomas, R.K., Schmoker, B. and Tsow, A.W., 2015. Cyber denial, deception and counter deception. Advances in Information Security, 64.

[21] Humayed, A., Lin, J., Li, F. and Luo, B., 2017. Cyber-physical systems security—A survey. IEEE Internet of Things Journal, 4(6), pp.1802-1831.

[22] Johnson, M., 2016. Cyber crime, security and digital intelligence. Routledge.

[23] Jouini, M., Rabai, L.B.A. and Khedri, R., 2015. A multidimensional approach towards a quantitative assessment of security threats. Procedia Computer Science, 52, pp.507-514.

[24] Junejo, K.N. and Goh, J., 2016, May. Behaviour-based attack detection and classification in cyber physical systems using machine learning. In Proceedings of the 2nd ACM international workshop on cyber-physical system security (pp. 34-43).

[25] Kennedy, K.A., 2017. Management and mitigation of insider threats. In Handbook of Behavioral Criminology (pp. 485-499). Cham: Springer International Publishing.

[26] Kim, P.T., 2016. Data-driven discrimination at work. Wm. & Mary L. Rev., 58, p.857.

[27] Kingori, P. and Gerrets, R., 2016. Morals, morale and motivations in data fabrication: Medical research fieldworkers views and practices in two Sub-Saharan African contexts. Social science & medicine, 166, pp.150-159.

[28] Korkali, M., Veneman, J.G., Tivnan, B.F., Bagrow, J.P. and Hines, P.D., 2017. Reducing cascading failure risk by increasing infrastructure network interdependence. Scientific reports, 7(1), p.44499.

[29] Lawless, W.F. and Sofge, D.A., 2017. Evaluations: autonomy and artificial intelligence: a threat or savior?. In Autonomy and artificial intelligence: a threat or savior? (pp. 295-316). Cham: Springer International Publishing.

[30] Lemley, M.A., 2015. IP in a World without Scarcity. NyUL Rev., 90, p.460.

[31] Livingstone, D. and Lewis, P., 2016. Space, the Final Frontier for Cybersecurity?. Chatham House. The Royal Institute of International Affairs.

[32] Lockwood, G.K., Hazen, D., Koziol, Q., Canon, R.S., Antypas, K., Balewski, J., Balthaser, N., Bhimji, W., Botts, J., Broughton, J. and Butler, T.L., 2017. Storage 2020: A vision for the future of hpc storage.

[33] Luo, F., Zhao, J., Dong, Z.Y., Chen, Y., Xu, Y., Zhang, X. and Wong, K.P., 2015. Cloud-based information infrastructure for next-generation power grid: Conception, architecture, and applications. IEEE Transactions on Smart Grid, 7(4), pp.1896-1912.

[34] Malikireddy, S.K.R. and Algubelli, B.R., 2017. Multidimensional privacy preservation in distributed computing and big data systems: Hybrid frameworks and emerging paradigms. International Journal of Scientific Research in Science and Technology, 3(4), pp.2395-602.

[35] McLaughlin, S., Konstantinou, C., Wang, X., Davi, L., Sadeghi, A.R., Maniatakos, M. and Karri, R., 2016. The cybersecurity landscape in industrial control systems. Proceedings of the IEEE, 104(5), pp.1039-1057.

[36] Mehan, J., 2016. Insider threat: A guide to understanding, detecting, and defending against the enemy from within. IT Governance Ltd.

[37] Mennen, M.G. and Van Tuyll, M.C., 2015. Dealing with future risks in the Netherlands: the National Security Strategy and the National Risk Assessment. Journal of Risk Research, 18(7), pp.860-876.

[38] Modarres, M., Kim, I.S., Ganguly, A. and Assessment, R., 2017. 4.2 Methodological Approaches in PRA for Critical Infrastructure. School of Social Sciences, p.33.

[39] Mohsin, M., Sardar, M.U., Hasan, O. and Anwar, Z., 2017. IoTRiskAnalyzer: A probabilistic model checking based framework for formal risk analytics of the Internet of Things. IEEE Access, 5, pp.5494-5505.

[40] Morris, J.W., 2015. Curation by code: Infomediaries and the data mining of taste. European journal of cultural studies, 18(4-5), pp.446-463.

[41] Mourtzis, D. and Vlachou, E., 2016. Cloud-based cyber-physical systems and quality of services. The TQM Journal, 28(5), pp.704-733.

[42] O’Brolcháin, F., Jacquemard, T., Monaghan, D., O’Connor, N., Novitzky, P. and Gordijn, B., 2016. The convergence of virtual reality and social networks: threats to privacy and autonomy. Science and engineering ethics, 22(1), pp.1-29.

[43] Omopariola, M., 2017. AI-Enhanced Threat Detection for National-Scale Cloud Networks: Frameworks, Applications, and Case Studies. ResearchGate Preprint.

[44] Onovo, A.A., Nta, I.E., Onah, A.A., Okolo, C.A., Aliyu, A., Dakum, P., Atobatele, A.O. and Gado, P., 2015. Partner HIV serostatus disclosure and determinants of serodiscordance among prevention of mother to child transmission clients in Nigeria. BMC public health, 15(1), p.827.

[45] Oughton, E.J., Tran, M.A.R.T.I.N.O., Jones, C.B. and Ebrahimy, R.A.Z.G.A.R., 2016. Digital communications and information systems. In The Future of National Infrastructure (p. 181). Cambridge University Press.

[46] Patriarca, R., Bergström, J. and Di Gravio, G., 2017. Defining the functional resonance analysis space: Combining Abstraction Hierarchy and FRAM. Reliability Engineering & System Safety, 165, pp.34-46.

[47] Petit, F., Verner, D., Brannegan, D., Buehring, W., Dickinson, D., Guziel, K., Haffenden, R., Phillips, J. and Peerenboom, J., 2015. Analysis of critical infrastructure dependencies and interdependencies (No. ANL/GSS-15/4). Argonne National Laboratory (ANL), Argonne, IL (United States).

[48] Porter, M.E. and Heppelmann, J.E., 2015. How smart, connected products are transforming companies. Harvard business review, 93(10), pp.96-114.

[49] Punithavathani, D.S., Sujatha, K. and Jain, J.M., 2015. Surveillance of anomaly and misuse in critical networks to counter insider threats using computational intelligence. Cluster Computing, 18(1), pp.435-451.

[50] Ramprasad, R., Batra, R., Pilania, G., Mannodi-Kanakkithodi, A. and Kim, C., 2017. Machine learning in materials informatics: recent applications and prospects. npj Computational Materials, 3(1), p.54.

[51] Ravi, V. and Kamaruddin, S., 2017, November. Big data analytics enabled smart financial services: opportunities and challenges. In International conference on big data analytics (pp. 15-39). Cham: Springer International Publishing.

[52] Sandberg, J., 2015. Human element of corporate espionage risk management: literature review on assessment and control of outsider and insider threats. University of Tampere.

[53] Simon, S. and de Goede, M., 2015. Cybersecurity, bureaucratic vitalism and European emergency. Theory, Culture & Society, 32(2), pp.79-106.

[54] Smith, O., Johnson, J. and Oscar, E., 2017. Rethinking Cyber Defense: Zero-Trust Implementation in Nigeria's Cloud Ecosystem.

[55] Sood, A.K., Zeadally, S. and Bansal, R., 2015. Exploiting trust: stealthy attacks through socioware and insider threats. IEEE Systems Journal, 11(2), pp.415-426.

[56] Sperotto, A., Molina, J.L., Torresan, S., Critto, A. and Marcomini, A., 2017. Reviewing Bayesian Networks potentials for climate change impacts assessment and management: A multi-risk perspective. Journal of environmental management, 202, pp.320-331.

[57] Wang, J., Gupta, M. and Rao, H.R., 2015. Insider threats in a financial institution. MIS quarterly, 39(1), pp.91-112.

[58] Wittkop, J., 2016. Building a comprehensive IT security program: practical guidelines and best practices. Apress.

[59] Zio, E., 2016. Challenges in the vulnerability and risk analysis of critical infrastructures. Reliability Engineering & System Safety, 152, pp.137-150.

[60] Zuech, R., Khoshgoftaar, T.M. and Wald, R., 2015. Intrusion detection and big heterogeneous data: a survey. Journal of Big Data, 2(1), p.3.

How to cite this paper

Bisola Akeju, Joseph Edivri, Jolly I. Ogbole, Precious Osobhalenewie Okoruwa, Oladapo Fadayomi, Toyosi O Abolaji "Conceptual Model for Insider Threat Classification and Risk Modeling in Complex Digital Systems" Iconic Research And Engineering Journals Volume 1 Issue 9 2018 Page 476-492 https://doi.org/10.64388/IREV1I9-1713778
Bisola Akeju, Joseph Edivri, Jolly I. Ogbole, Precious Osobhalenewie Okoruwa, Oladapo Fadayomi, Toyosi O Abolaji "Conceptual Model for Insider Threat Classification and Risk Modeling in Complex Digital Systems" Iconic Research And Engineering Journals, vol. 1, no. 9, Mar. 2018, doi: https://doi.org/10.64388/IREV1I9-1713778
Bisola Akeju, Joseph Edivri, Jolly I. Ogbole, Precious Osobhalenewie Okoruwa, Oladapo Fadayomi, Toyosi O Abolaji (2018). Conceptual Model for Insider Threat Classification and Risk Modeling in Complex Digital Systems. Iconic Research And Engineering Journals, 1(9). doi: https://doi.org/10.64388/IREV1I9-1713778
Bisola Akeju, Joseph Edivri, Jolly I. Ogbole, Precious Osobhalenewie Okoruwa, Oladapo Fadayomi, Toyosi O Abolaji "Conceptual Model for Insider Threat Classification and Risk Modeling in Complex Digital Systems" Iconic Research And Engineering Journals, vol. 1, no. 9, Mar. 2018. Crossref, https://doi.org/10.64388/IREV1I9-1713778
@article{1713778,
      author = {Bisola Akeju, Joseph Edivri, Jolly I. Ogbole, Precious Osobhalenewie Okoruwa, Oladapo Fadayomi, Toyosi O Abolaji},
      title = {Conceptual Model for Insider Threat Classification and Risk Modeling in Complex Digital Systems},
      journal = {Iconic Research And Engineering Journals},
      year = {2018},
      volume = {1},
      number = {9},
      pages = {476-492},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1713778.pdf},
      abstract = {Insider threats remain one of the most persistent and complex challenges in contemporary cybersecurity, particularly within highly interconnected, data-intensive, and adaptive digital environments. Unlike external attacks, insider threats originate from trusted identities with legitimate access, making detection, attribution, and mitigation inherently difficult. This proposes a conceptual model for insider threat classification and risk modeling tailored to complex digital systems, including cloud-native platforms, distributed enterprise architectures, and cyber?physical ecosystems. The model addresses critical limitations of existing approaches, which often rely on static classifications, isolated behavioral indicators, or retrospective analysis, and therefore struggle to capture the dynamic, contextual, and systemic nature of insider risk. The proposed framework integrates two tightly coupled layers: an insider threat classification layer and a dynamic risk modeling layer. The classification layer systematically categorizes insiders based on intent (malicious, negligent, or compromised), capability, access privilege, behavioral patterns, and temporal characteristics, leveraging multi-source data such as activity logs, system context, and behavioral deviations. The risk modeling layer conceptualizes insider risk as a probabilistic and continuously evolving construct, driven by the interaction between insider behavior, asset criticality, system interdependencies, and organizational controls. Advanced modeling approaches, including probabilistic inference, temporal risk scoring, and scenario-based analysis, are incorporated to account for uncertainty, nonlinearity, and cascading effects within complex digital systems. A central contribution of the model lies in its integration mechanism, where classification outcomes dynamically inform risk scores, while evolving risk profiles feedback into reclassification and monitoring priorities. This closed-loop design supports real-time risk awareness, adaptive control strategies, and proactive intervention. Additionally, the model explicitly incorporates governance, ethical, and privacy considerations to ensure responsible deployment within enterprise and critical infrastructure contexts. By providing a unified, system-oriented perspective, the conceptual model advances insider threat research and practice, offering a foundation for resilient security architectures, improved decision-making, and future empirical validation in high-velocity digital environments.},
      keywords = {Insider Threat, Risk Modeling, Threat Classification, Complex Digital Systems, Cybersecurity Governance, Behavioral Analytics, Enterprise Security},
      month = {March},
      doi = {https://doi.org/10.64388/IREV1I9-1713778}
  }