Traditional perimeter-centric security is fundamentally ill-equipped to intercept adversaries operating with valid system credentials. This research presents the Malicious Insider Detection System (MIDS), a framework that identifies internal risks through the longitudinal analysis of high-resolution system telemetry. Our approach leverages an ensemble architecture to pinpoint temporal anomalies in user behavior, specifically focusing on authentication sequences and file-system interaction density. Validated against the CERT Insider Threat Dataset (v6.2), the MIDS framework achieved a 96.4% Detection Rate (DR) with a marginal False Positive Rate (FPR) of 1.1%. These metrics demonstrate that combining time-series modeling with robust classification provides a high-performance solution for enterprise threat mitigation.
K et al. (Sun,) studied this question.