BEHAVIORAL-AWARE DECISION SUPPORT SYSTEM FOR CYBER RISK ASSESSMENT IN CRITICAL INFRASTRUCTURE BASED ON USER ACTIVITY ANALYSIS

Authors

DOI:

https://doi.org/10.31673/2409-7292.2026.037818

Abstract

This paper proposes an intelligent decision support system for cyber risk assessment in critical infrastructure based
on user behavior analysis. The proposed approach combines two-stage behavioral analysis of users before and after
authentication, machine learning methods for anomaly detection, and Bayesian cyber risk assessment within a unified
analytical architecture. A mechanism for integrating technical security events, user behavioral characteristics, and
contextual factors to form an integrated risk profile is developed. Isolation Forest, XGBoost, and LSTM models are
employed for behavioral anomaly detection, while a Bayesian network is used for risk assessment, enabling the
consideration of uncertainty and causal relationships among risk factors. Experimental evaluation conducted on the CERT
Insider Threat, LANL User Authentication, and CICIDS2017 datasets confirmed the effectiveness of the proposed
approach. The LSTM model achieved the best anomaly detection performance, reaching ROC-AUC values of 0.96 for
pre-authentication analysis and 0.97 for post-authentication analysis. The proposed system achieved a cyber risk
classification accuracy of 0.91 and a recommendation precision of 0.89 with an average response time of 87 ms. The
practical significance of the study lies in enabling the transition from anomaly detection to comprehensive cyber risk
assessment and the generation of response recommendations for potential threats in critical infrastructure environments.
Keywords: cybersecurity, critical infrastructure, decision support system, cyber risk assessment, user behavior
analysis, UBA, UEBA, machine learning, anomaly detection, Bayesian networks, LSTM, XGBoost.

References
1. Eberle W., Holder L. Insider Threat Detection Using Graph-Based Approaches // Cybersecurity Applications
& Technology Conference for Homeland Security. 2009. P. 237–241. DOI: 10.1109/CATCH.2009.7.
2. Salem M. B., Stolfo S. J. Modeling User Search Behavior for Masquerade Detection // Recent Advances in
Intrusion Detection. Berlin : Springer, 2011. P. 181-200. DOI: 10.1007/978-3-642-23644-0_10.
3. Legg P. A., Buckley O., Goldsmith M., Creese S. Automated Insider Threat Detection System Using User and
Role-Based Profile Assessment // IEEE Systems Journal. 2017. Vol. 11, No. 2. P. 503–512. DOI: 10.1109/JSYST.
2015.2438442.
4. Liu F. T., Ting K. M., Zhou Z.-H. Isolation Forest // Proceedings of the Eighth IEEE International Conference
on Data Mining. 2008. P. 413-422. DOI: 10.1109/ICDM.2008.17.
5. Breiman L. Random Forests // Machine Learning. 2001. Vol. 45, No. 1. P. 5–32. DOI: 10.1023/A:
1010933404324.
6. Chen T., Guestrin C. XGBoost: A Scalable Tree Boosting System // Proceedings of the 22nd ACM SIGKDD
International Conference on Knowledge Discovery and Data Mining. 2016. P. 785–794. DOI: 10.1145/2939672.2939785.
7. Malhotra P., Ramakrishnan A., Anand G., Vig L., Agarwal P., Shroff G. LSTM-Based Encoder-Decoder for
Multi-Sensor Anomaly Detection // ICML Workshop on Anomaly Detection. 2016.
8. Sakurada M., Yairi T. Anomaly Detection Using Autoencoders with Nonlinear Dimensionality Reduction //
Proceedings of the 2nd Workshop on Machine Learning for Sensory Data Analysis. 2014. P. 4-11. DOI:
10.1145/2689746.2689747.
9. Poolsappasit N., Dewri R., Ray I. Dynamic Security Risk Management Using Bayesian Attack Graphs // IEEE
Transactions on Dependable and Secure Computing. 2012. Vol. 9, No. 1. P. 61–74. DOI: 10.1109/TDSC.2011.34.
10. Frigault M., Wang L. Measuring Network Security Using Bayesian Network-Based Attack Graphs //
Proceedings of the 32nd Annual IEEE International Computer Software and Applications Conference. 2008. P. 698–703.
DOI: 10.1109/COMPSAC.2008.89.

Published

2026-09-15

Issue

Section

Articles