<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>Iranian Society of Cryptology</PublisherName>
				<JournalTitle>The ISC International Journal of Information Security</JournalTitle>
				<Issn>2008-2045</Issn>
				<Volume></Volume>
				<Issue>Articles in Press</Issue>
				<PubDate PubStatus="epublish">
					<Year>2026</Year>
					<Month>02</Month>
					<Day>22</Day>
				</PubDate>
			</Journal>
<ArticleTitle>An LSTM-DBSCAN Approach for Interpretable Insider Threat Detection via Behavioural Anomaly Analysis</ArticleTitle>
<VernacularTitle></VernacularTitle>
			<FirstPage></FirstPage>
			<LastPage></LastPage>
			<ELocationID EIdType="pii">241277</ELocationID>
			
<ELocationID EIdType="doi">10.22042/isecure.2026.241277</ELocationID>
			
			<Language>EN</Language>
<AuthorList>
<Author>
					<FirstName>Mohammad</FirstName>
					<LastName>Mohammadi</LastName>
<Affiliation>Department of Computer Engineering, Bozorgmehr University of Qaenat, Qaen, South Khorasan, Iran.</Affiliation>

</Author>
<Author>
					<FirstName>Moein</FirstName>
					<LastName>Bannaye Zahmati</LastName>
<Affiliation>Department of Computer Engineering, Bozorgmehr University of Qaenat, Qaen, South Khorasan, Iran.</Affiliation>

</Author>
<Author>
					<FirstName>Morteza</FirstName>
					<LastName>Noferesti</LastName>
<Affiliation>Department of Computer Engineering, Bozorgmehr University of Qaenat, Qaen, South Khorasan, Iran.</Affiliation>
<Identifier Source="ORCID">0009-0000-5507-1461</Identifier>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
		<Abstract>Insider threats pose a significant cybersecurity risk, as authorised users can exploit legitimate access to compromise sensitive systems and data. This paper proposes an integrated behavioural anomaly detection approach to address three critical challenges in AI-driven insider threat detection: lack of interpretability, misleading evaluation metrics, and misalignment with operational taxonomies. Our approach employs a three-stage pipeline: (1) an LSTM autoencoder to detect temporal anomalies in login patterns, (2) DBSCAN clustering to identify suspicious file access and device usage during anomalous sessions, and (3) DBSCAN-based URL analysis to uncover exfiltration patterns. By analysing behaviour across time, location, and web activity, this framework builds actionable threat chains mapped to MITRE ATT&amp;CK techniques including T1078, T1005, T1204.002, T1567.002. It bridges the gap between theoretical models and the daily work of a Security Operations Center (SOC). In the data exfiltration scenario on the CERT R6.2 insider threat dataset, the proposed approach achieved a recall of 83.3% and an accuracy of 91.7% in classifying malicious days. The framework also provides interpretable alerts and maintains operational efficiency. </Abstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">Insider threat detection</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">LSTM</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">DBSCAN clustering</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">MITRE ATT&amp;‌‌‌‌‌CK</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Behavioural anomaly analysis</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://www.isecure-journal.com/article_241277_0ad257017faaa93a6b0ec2325482290a.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
