Forensic framework for insider threat detection and mitigation in corporate networks.

No Thumbnail Available
Date
2026
Journal Title
Journal ISSN
Volume Title
Publisher
Busitema University
Abstract
Insider threats present severe risks to corporate networks due to the authorized access privileges and contextual knowledge of internal users. This study designed and evaluated an integrated, proactive forensic framework using Design Science Research Methodology (DSRM) to enhance early threat detection and mitigation in Ugandan corporate networks focusing on banking, fintech and telecommunications sectors. The proposed framework integrates User and Entity Behavior Analytics (UEBA), real-time monitoring and automated response orchestration using open-source technologies including Wazuh, Elastic Stack, Apache Kafka and custom machine learning models (Isolation Forest, Autoencoder, and Long Short-Term Memory). The framework was evaluated using a multimethod strategy including expert Delphi review, controlled laboratory simulations and a quasiexperimental field study across twelve corporate environments. Expert review achieved strong consensus on design feasibility and forensic readiness (Cronbach’s alpha = 0.89). In controlled simulations, the proposed framework achieved a 91.5% detection rate compared with 67.3% for the rule-based SIEM baseline, reducing Mean Time to Detect (MTTD) from 47.2 to 8.3 minutes and lowering the false positive rate from 34.2% to 12.8%. The field observations during a three-month post-intervention period (April–June 2026) showed shorter containment times with Mean Time to Contain (MTTC) recorded at 18.7 hours compared to a literature-derived baseline of 96.3 hours. These findings demonstrate that integrating behavioral analytics and automated containment can improve threat detection, incident response and forensic readiness in resource-constrained corporate networks without the high costs of proprietary solutions.
Description
Dissertation
Keywords
Citation
Kakaire, G. (2026). Forensic framework for insider threat detection and mitigation in corporate networks. [Unpublished undergraduate research report].Busitema University.