← all papers · overview

Algorithms and software architecture for automated user behaviour analysis in cyber threat detection systems

Abstract

The relevance of the present study is determined increasing complexity of cyber threats and the limited effectiveness of traditional detection methods, which necessitates the implementation of intelligent behavioural approaches using modern algorithmic and language models. The purpose of this study was to generalise and conceptually reinterpret approaches to automated user behaviour analysis in cyber threat detection systems from the perspective of algorithmic solutions and architectural principles of their construction. The study, based on theoretical analysis, a systemic approach, and comparative analysis, demonstrates that user behaviour analysis is an effective approach to cyber threat detection, capable of complementing and surpassing classical signature-based methods through the identification of context-dependent anomalies and multi-stage attacks. Comparative analysis of approaches to User and Entity Behaviour Analytics established a transition from a focus on individual actions to comprehensive analysis of interactions between users and technical components, which increases the accuracy of threat detection and reduces the number of falsepositive alerts. Systemic analysis of the architecture of contemporary cybersecurity platforms showed that the integration of large language models ensures unified processing of structured, semi-structured, and unstructured data, modelling of long-term inter-event dependencies, and development of contextual behavioural models in real-time. Conceptual analysis and analytical evaluation indicated that combining behavioural analysis with large language models creates adaptive, scalable, and risk-oriented cybersecurity systems capable of early detection and proactive response to contemporary cyber threats while maintaining explainability, security, and regulatory compliance. The findings may support the design and implementation of intelligent cybersecurity systems in security operations and monitoring centres, security information and event management systems, and platforms for security orchestration, automation, and incident response

Related papers

Ranked by semantic similarity — how closely each paper's abstract matches this one (100% = near-identical topic).