Methods for analyzing user behavior in information systems

Free access

This article examines methods for analyzing user behavior in information systems, focusing on identifying anomalies and preventing security threats. The authors highlight the growing risk of cyberattacks, emphasizing that 79% of data breaches result from human actions, whether intentional or accidental. Traditional security measures like firewalls and antivirus software are insufficient, necessitating advanced behavioral analysis to detect unusual activities early. The study presents a classification of methods for analyzing user behavior, including anomaly detection, event sequence analysis, classification techniques, network interaction analysis, text analysis, and neural network-based approaches. Each method is evaluated based on criteria such as accuracy, implementation complexity, adaptability, training time, and comprehensiveness. The Euclidean distance metric is applied to compare these methods, revealing that event sequence analysis is the most effective for identifying deviations in user behavior. The findings underscore the importance of integrating multiple analytical approaches to enhance security systems. By combining methods like statistical analysis, machine learning, and graph algorithms, organizations can better detect both simple anomalies and complex threats. The article provides valuable insights for improving information security strategies, advocating for a proactive approach to mitigate risks posed by internal and external threats.

information security \ internal intruder \ analyzing user behavior \ analyzing event sequence \ anomaly analysis

Short address: https://sciup.org/149151782

IDS: 149151782   |   UDC: 004.775   |   DOI: 10.15688/NBIT.jvolsu.2025.1.1