Insider threat detection faces major challenges in the form of high false positive rates and limited interpretability in single machine learning models. This study proposes the Explainable User and Entity Behavior Analytics (X-UEBA) framework, which integrates Isolation Forest for static anomaly detection and Stacked BiLSTM for temporal patterns, enhanced by a domain-knowledge-based Logic Injection mechanism. Unlike conventional hybrid approaches, this system employs dynamic risk score fusion with threshold optimization (F1-Score Optimized Thresholding) to address extreme class imbalance. Experimental results on the CERT r4.2 dataset show that the model achieves an AUC of 0.68 with a sensitivity (Recall) of 43% against valid attacks. The system proved effective in reducing operational overhead by filtering out 261,967 normal activities (significantly reduced search space), while SHAP integration provides transparency into detection decisions. This research contributes to delivering a security solution that balances adaptive detection coverage with operational validity that analysts can trust.
Copyrights © 2026