Abstract
Insider threats represent a criticalchallenge in modern cybersecurity due to the misuse of legitimate access by authorized users. Conventional detection approaches, including rule-based and signature-based systems, are limited in identifying unknown and evolving threats because they lack adaptability and contextual awareness. This paper presents a comprehensive survey of recent advancements in insider threat detection and introduces CogniShield, a context-aware detection framework. Existing methods are categorized into behavioural analytics, anomaly detection, deep learning-based techniques, and sequence modelling approaches. A detailed analysis highlights key limitations such as high false positive rates, insufficient temporal modelling, and limited integration of heterogeneous data sources. To address these issues, the proposed framework integrates Deep Learning, Natural Language Processing (NLP), and Time-Series Analysis to enable intelligent, scalable, and real-time threat detection. Thesystemfurtherincorporatescontextual understanding and dynamic risk scoring to enhance accuracy and support proactive security management.