An Explainable Hybrid Behavioral Analytics Framework for Insider Threat Detection in Hypervisor-Based Cloud Environments

  • Onuma Divine Anele Department of Computer Science, Rivers State University, Nkpolu-Oroworukwo, Port Harcourt, Rivers State, Nigeria.
  • Onyeche Princewill Nweke Department of Computer Science, Rivers State University, Nkpolu-Oroworukwo, Port Harcourt, Rivers State, Nigeria.
  • Eugene-Jaja Michael Telema Department of Computer Science, Rivers State University, Nkpolu-Oroworukwo, Port Harcourt, Rivers State, Nigeria.
Keywords: Hypervisor Security, Insider Threat Detection, Explainable Artificial Intelligence (XAI), User and Entity Behavior Analytics (UEBA), Hybrid Artificial Intelligence, Behavioral Analytics, Virtual Machine Introspection (VMI), Hypervisor Telemetry, Cloud Security, Dynamic Risk Scoring

Abstract

Insider threats remain one of the most challenging cybersecurity problems in hypervisor-based cloud environments because privileged users can exploit legitimate access to compromise virtual machines, manipulate hypervisor configurations, and exfiltrate sensitive data without triggering conventional security mechanisms. Existing approaches largely focus on enterprise user activities and rarely integrate hypervisor telemetry, behavioral analytics, Explainable Artificial Intelligence (XAI), and automated response into a unified framework. This study designed and developed an Explainable Hybrid Behavioral Analytics Framework for insider threat detection in hypervisor-based cloud environments. The study adopted the Design Science Research Methodology (DSRM) to design, implement, and evaluate the proposed framework. Hypervisor telemetry, virtual machine lifecycle events, privileged user activities, and behavioral logs were processed using User and Entity Behavior Analytics (UEBA), while a hybrid artificial intelligence engine integrating Random Forest, XGBoost, Long Short-Term Memory (LSTM), Autoencoder, and Isolation Forest were employed for threat detection. Explainability was achieved using SHAP and LIME, with dynamic risk scoring and automated response supporting real-time mitigation. Experimental evaluation using the CERT Insider Threat, LANL, and TWOS datasets achieved accuracies of 98.70%, 97.90%, and 98.30%, respectively, with F1-scores ranging from 97.35% to 98.25%, false positive rates of 1.20–1.60%, detection latency of 42–55 ms, and explainability scores of 0.91–0.93. The study concludes that integrating hypervisor telemetry, hybrid AI, and XAI provides an accurate, transparent, scalable, and proactive solution for insider threat detection in modern hypervisor-based cloud infrastructures.

Downloads

Download data is not yet available.

References

Abusitta, A., Li, M. Q., & Fung, B. C. M. (2024). Survey on explainable AI: Techniques, challenges and open issues. Expert Systems with Applications, 255, 124710. https://doi.org/10.1016/j.eswa.2024.124710

Adeduro, O., Josh-Falade, O., & Mesioye, A. (2026). Proactive insider threat detection framework: An explainable AI and behavioral analytics-driven approach. Journal of Future Artificial Intelligence and Technologies. Advance online publication. https://doi.org/10.62411/faith.3048-3719-307

Asha, S., & Shanmugapriya, D. (2024). Understanding insiders in cloud adopted organizations: A survey on taxonomies, incident analysis, defensive solutions, challenges. Future Generation Computer Systems, 158, 427–446. https://doi.org/10.1016/j.future.2024.04.033

Alketbi, K. S., & Mehmood, A. (2025). A comprehensive survey of explainable artificial intelligence techniques for malicious insider threat detection. IEEE Access, 13, 121772–121798. https://doi.org/10.1109/ACCESS.2025.3587114

Altaee, S., & Sweidan, M. (2026). Artificial intelligence-based insider-threat detection: A hybrid explainable framework with automated response and privilege containment. Computers, 15(7), 426. https://doi.org/10.3390/computers15070426

Alzaabi, F. R., & Mehmood, A. (2024). A review of recent advances, challenges, and opportunities in malicious insider threat detection using machine learning methods. IEEE Access, 12, 30907–30927. https://doi.org/10.1109/ACCESS.2024.3369906

Azaria, A., Richardson, A., Kraus, S., & Subrahmanian, V. S. (2014). Behavioral analysis of insider threat: A survey and bootstrapped prediction in imbalanced data. IEEE Transactions on Computational Social Systems, 1(2), 135–155. https://doi.org/10.1109/TCSS.2014.2377811

Bahram, S., Jiang, X., Wang, Z., Grace, M., Li, J., Srinivasan, D., Rhee, J., & Xu, D. (2010). DKSM: Subverting virtual machine introspection for fun and profit. Proceedings of the IEEE Symposium on Reliable Distributed Systems.

Bugiel, S., Nürnberger, S., Pöppelmann, T., & Sadeghi, A.-R. (2012). Virtualization security: Current trends and future directions.

Bugiel, S., Nürnberger, S., Pöppelmann, T., Sadeghi, A.-R., & Schneider, T. (2012). Twin clouds: Secure cloud computing with low latency. In Communications and Multimedia Security.

Butt, K., Nasir, A., Hussain, B., Raza, M., Khan, S., Anwar, S., Ahmed, A., & Shah, K. (2026). Behavioral analytics for insider threat detection in cloud environments. ResearchGate preprint. https://www.researchgate.net/publication/404525592_Behavioral_Analytics_for_Insider_Threat_Detection_in_Cloud_Environments

Cheimonidis, P., & Rantos, K. (2023). Dynamic risk assessment in cybersecurity: A systematic literature review. Future Internet, 15(10), 324. https://doi.org/10.3390/fi15100324

Cheon, J. H., Kim, A., Kim, M., & Song, Y. (2017). Homomorphic encryption for arithmetic of approximate numbers. In Advances in Cryptology – ASIACRYPT 2017 (pp. 409–437). https://doi.org/10.1007/978-3-319-70694-8_15

Cloud Security Alliance. (2024). Security guidance for critical areas of focus in cloud computing.

Dwork, C., & Roth, A. (2014). The algorithmic foundations of differential privacy. Foundations and Trends® in Theoretical Computer Science, 9(3–4), 211–407. https://doi.org/10.1561/0400000042

Evans, D., Kolesnikov, V., & Rosulek, M. (2018). A pragmatic introduction to secure multi-party computation. Foundations and Trends® in Privacy and Security, 2(2–3), 70–246. https://doi.org/10.1561/3300000019

Faqihi, R., Nanda, P., Mohanty, M., Alqahtani, S., & Alrashed, B. (2026). Towards trustworthy cybersecurity: Reclassifying insider threat detection. Future Generation Computer Systems, 183, 108543. https://doi.org/10.1016/j.future.2026.108543

Garfinkel, T., & Rosenblum, M. (2003). A virtual machine introspection based architecture for intrusion detection. Proceedings of the Network and Distributed Systems Security Symposium (NDSS).

Gaur, A., Mishra, P., Singh, A., Vinod, P., et al. (2024). vDefender: An explainable and introspection-based approach for identifying emerging malware behaviour at hypervisor-layer in virtualization environment. Computers & Electrical Engineering, 120, 109742. https://doi.org/10.1016/j.compeleceng.2024.109742

Gong, Y., Cui, S., Liu, S., Jiang, B., Dong, C., & Lu, Z. (2024). Graph-based insider threat detection: A survey. Computer Networks, 254, 110757. https://doi.org/10.1016/j.comnet.2024.110757

Greitzer, F. L., & Frincke, D. A. (2010). Combining traditional cyber security audit data with psychosocial data: Towards predictive modeling for insider threat mitigation. In Insider Threats in Cyber Security (pp. 85–113).

Kairouz, P., McMahan, H. B., Avent, B., et al. (2021). Advances and open problems in federated learning. Foundations and Trends® in Machine Learning, 14(1–2), 1–210. https://doi.org/10.1561/2200000083

Khan, A. H. (2025). AI and behavioral analytics for insider threat detection: A comprehensive review of techniques, datasets, and emerging challenges. Journal of Information Systems Engineering and Management, 10(63s).

Kindervag, J. (2010). Build security into your network's DNA: The Zero Trust Network Architecture. Forrester Research.

Lanuwabang, L., & Sarasu, P. (2025). Detection of anomalies based on user behavioral information: A survey. International Journal of Wireless and Microwave Technologies, 15(3), 54–65. https://doi.org/10.5815/IJWMT.2025.03.04

Mell, P., & Grance, T. (2011). The NIST definition of cloud computing (NIST Special Publication 800-145). National Institute of Standards and Technology.

Mol, J. (2026). Explainable AI mechanisms for insider threat detection in cloud-native platforms. International Journal of Computer Science and Information Management, 3(1).

Nance, K., Losiouk, E., & Hay, B. (2014). Virtual machine introspection: Towards bridging the semantic gap. Journal of Cloud Computing, 3(16). https://doi.org/10.1186/s13677-014-0016-2

National Institute of Standards and Technology. (2020). Zero Trust Architecture (NIST Special Publication 800-207). U.S. Department of Commerce.

Ofusori, L., Bokaba, T., & Mhlongo, S. (2024). Artificial intelligence in cybersecurity: A comprehensive review and future direction. Journal of Intelligent & Fuzzy Systems. https://doi.org/10.1080/08839514.2024.2439609

OpenStack Foundation. (2024). OpenStack documentation.

Perez-Botero, D., Szefer, J., & Lee, R. B. (2013). Characterizing hypervisor vulnerabilities in cloud computing servers. Proceedings of the International Workshop on Security in Cloud Computing.

Pfoh, J., Schneider, C., & Eckert, C. (2011). A formal model for virtual machine introspection. Springer.

Prasad, P. S. S., Nayak, S. K., & Krishna, M. V. (2025). Hybrid machine learning for enhanced insider threat detection using generative latent features. International Journal of Engineering Trends and Technology, 73(6), 102–113. https://doi.org/10.14445/22315381/IJETT-V73I6P110

Rjoub, G., Bentahar, J., Abdel Wahab, O., Mizouni, R., Song, A., Cohen, R., Otrok, H., & Mourad, A. (2023). A survey on explainable artificial intelligence for cybersecurity. IEEE Transactions on Network and Service Management, 20(4), 5115–5140. https://doi.org/10.1109/TNSM.2023.3282740

Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207

Salih, A., Raisi-Estabragh, Z., Boscolo Galazzo, I., Radeva, P., Petersen, S. E., Menegaz, G., & Lekadir, K. (2023). A perspective on explainable artificial intelligence methods: SHAP and LIME. arXiv. https://arxiv.org/abs/2305.02012

Samuel, K. (2026). Behavioral analytics and explainable AI for identifying insider threats in government agencies. ResearchGate.

Sánchez-García, I. D., Mejía, J., & Gilabert, T. S. F. (2023). Cybersecurity risk assessment: A systematic mapping review, proposal, and validation. Applied Sciences, 13(1), 395. https://doi.org/10.3390/app13010395

Sarraf, S. (2026). Behavioral analytics for continuous insider threat detection in Zero Trust architectures. arXiv. https://arxiv.org/abs/2601.06708

Saxena, D., Gupta, I., Gupta, R., Singh, A. K., & Wen, X. (2023). An AI-driven VM threat prediction model for multi-risks analysis-based cloud cybersecurity. IEEE Transactions on Systems, Man, and Cybernetics: Systems. https://doi.org/10.1109/TSMC.2023.3288081

Sehestedt, J., et al. (2024). Active and passive virtual machine introspection on AMD and ARM processors. Journal of Systems Architecture, 149, 103101. https://doi.org/10.1016/j.sysarc.2024.103101

Selvam, P. A., & Selvy, P. T. (2025). Explainable AI (XAI) for insider threat detection: Balancing security and transparency in cloud computing. Concurrency and Computation: Practice and Experience, 37(25–26), e70390. https://doi.org/10.1002/cpe.70390

Song, S., Gao, N., Zhang, Y., et al. (2024). BRITD: Behavior rhythm insider threat detection with time awareness and user adaptation. Cybersecurity, 7, 2. https://doi.org/10.1186/s42400-023-00190-9

Stefan, D., et al. (2020). Towards hypervisor support for enhancing the performance of virtual machine introspection. Future Generation Computer Systems, 108, 1110–1123.

Thammaiah, N., Girish, N., Meghana, N., Shivaprakash, G., & Kenny, S. P. K. (2026). An interpretable insider threat detection framework: Correlating digital communications and behavioral metadata. In Proceedings of the 18th International Conference on Agents and Artificial Intelligence (ICAART 2026) (Vol. 1, pp. 864–871). https://doi.org/10.5220/0014685300004052

Tian, T., Zhang, C., Jiang, B., et al. (2025). Insider threat detection for specific threat scenarios. Cybersecurity, 8, 17. https://doi.org/10.1186/s42400-024-00321-w

VMware. (2024). VMware ESXi Architecture and Security Guide.

Wang, W., et al. (2017). Leveraging virtual machine introspection with memory forensics to detect and characterize unknown malware using machine learning techniques at the hypervisor. Digital Investigation, 23, 99–123. https://doi.org/10.1016/j.diin.2017.10.004

Peffers, K., Tuunanen, T., Rothenberger, M. A., & Chatterjee, S. (2007). A Design Science Research Methodology for Information Systems Research. Journal of Management Information Systems, 24(3), 45–77. https://doi.org/10.2753/MIS0742-1222240302

Published
2026-08-08
How to Cite
Anele, O., Nweke, O., & Telema, E.-J. (2026). An Explainable Hybrid Behavioral Analytics Framework for Insider Threat Detection in Hypervisor-Based Cloud Environments. GPH-International Journal of Computer Science and Engineering, 9(1), 22-71. https://doi.org/10.5281/zenodo.21848848