BUSITEMA UNIVERSITY | LIBRARY
Log in
 
Repository logo
Repository logo
  • Submit an Item
  • Browse
  • English
  • Català
  • Čeština
  • Deutsch
  • Español
  • Français
  • Gàidhlig
  • Italiano
  • Latviešu
  • Magyar
  • Nederlands
  • Polski
  • Português
  • Português do Brasil
  • Suomi
  • Svenska
  • Türkçe
  • Tiếng Việt
  • Қазақ
  • বাংলা
  • हिंदी
  • Ελληνικά
  • Yкраї́нська
  • Log In
    New user? Click here to register.Have you forgotten your password?
  1. Home
  2. Browse by Author

Browsing by Author "Kakaire, Godfrey"

Now showing 1 - 1 of 1
Results Per Page
Sort Options
  • No Thumbnail Available
    Item
    Forensic framework for insider threat detection and mitigation in corporate networks.
    (Busitema University, 2026) Kakaire, Godfrey
    Insider threats present severe risks to corporate networks due to the authorized access privileges and contextual knowledge of internal users. This study designed and evaluated an integrated, proactive forensic framework using Design Science Research Methodology (DSRM) to enhance early threat detection and mitigation in Ugandan corporate networks focusing on banking, fintech and telecommunications sectors. The proposed framework integrates User and Entity Behavior Analytics (UEBA), real-time monitoring and automated response orchestration using open-source technologies including Wazuh, Elastic Stack, Apache Kafka and custom machine learning models (Isolation Forest, Autoencoder, and Long Short-Term Memory). The framework was evaluated using a multimethod strategy including expert Delphi review, controlled laboratory simulations and a quasiexperimental field study across twelve corporate environments. Expert review achieved strong consensus on design feasibility and forensic readiness (Cronbach’s alpha = 0.89). In controlled simulations, the proposed framework achieved a 91.5% detection rate compared with 67.3% for the rule-based SIEM baseline, reducing Mean Time to Detect (MTTD) from 47.2 to 8.3 minutes and lowering the false positive rate from 34.2% to 12.8%. The field observations during a three-month post-intervention period (April–June 2026) showed shorter containment times with Mean Time to Contain (MTTC) recorded at 18.7 hours compared to a literature-derived baseline of 96.3 hours. These findings demonstrate that integrating behavioral analytics and automated containment can improve threat detection, incident response and forensic readiness in resource-constrained corporate networks without the high costs of proprietary solutions.
Contact us for questions and to provide feedback.

Repository logo

  • Cookie settings
  • Privacy policy
  • End User Agreement
  • Send Feedback