Insider Threat Detection
Unsupervised anomaly detection pipeline for CMU CERT insider behavior data using Featuretools DFS, PCA dimensionality reduction, and Gaussian Mixture Models.
- Built feature synthesis over email, HTTP, device, file, logon, and psychometric logs.
- Used PCA to retain dominant behavioral variance before density-based anomaly scoring.
- Ran large processing workflows on USM's Magnolia HPC cluster with Slurm.