ENHANCING THE ARCHITECTURE OF AN INSIDER THREAT DETECTION SYSTEM THROUGH FILE ACTIVITY MONITORING

F. Muxamadiyev

Samarqand davlat universiteti ilmiy tadqiqotlar axborotnomasi · 2026-yil

Annotatsiya

This paper proposes an improvement of a client-server architecture designed to detect insider threats by monitoring file operations of users working with documents in real time. The study considers actions such as file creation, deletion, copying, printing, transfer to USB devices, and access to confidential files as key features. These features are grouped by time intervals using a sliding window mechanism and transformed into vector form for intelligent models. The model evaluates user activity as normal or anomalous and generates an alert or response action when a risky state is detected. Performing the main computational processes on the client side enables faster real-time analysis, reduces server load, and limits unnecessary transmission of confidential data. The proposed improved architecture can be integrated into DLP, SIEM, and UEBA systems as an additional module.

Maqola ma’lumotlari
MualliflarF. Muxamadiyev
JurnalSamarqand davlat universiteti ilmiy tadqiqotlar axborotnomasi
Nashr sanasi2026-07-01
Jild2
Son3
Betlar45-55
DOI10.59251/2181-3973.2025.v1.138.1.3953

Samarqand davlat universiteti ilmiy tadqiqotlar axborotnomasi jurnalidan boshqa maqolalar

Samarqand davlat universiteti ilmiy tadqiqotlar axborotnomasi — barcha maqolalar