Paper deep dive
Multi-Axis Trust Modeling for Interpretable Account Hijacking Detection
Mohammad AL-Smadi
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 94%
Last extracted: 7/20/2026, 9:48:04 PM
Summary
This paper proposes a Hadith-inspired multi-axis trust modeling framework for interpretable account hijacking detection. It translates five trust axes (integrity, precision, continuity, reputation, anomaly evidence) into 26 behavioral features and adds temporal features to capture short-horizon changes. The framework is evaluated on CLUE-LDS and CERT r6.2 datasets, demonstrating superior performance over raw-count and unsupervised baselines, with temporal features significantly improving robustness on the challenging CERT dataset.
Entities (10)
Relation Signals (8)
Mohammad AL-Smadi â affiliatedwith â Qatar University
confidence 99% ¡ Mohammad AL-Smadi Qatar University
Multi-Axis Trust Modeling â employs â Random Forest
confidence 95% ¡ a Random Forest trained on the trust features achieves near-perfect detection performance
Multi-Axis Trust Modeling â uses â CERT r6.2
confidence 95% ¡ evaluate the approach on the CERT Insider Threat Test Dataset r6.2
Multi-Axis Trust Modeling â uses â CLUE-LDS
confidence 95% ¡ We evaluate the framework on the CLUE-LDS cloud activity dataset
Multi-Axis Trust Modeling â appliedto â UEBA
confidence 90% ¡ Hadith-inspired trust axes provide an interpretable and effective foundation for UEBA
Multi-Axis Trust Modeling â defines â IsnÄd
confidence 90% ¡ contextual continuity (isnÄd)
Multi-Axis Trust Modeling â defines â á¸abáš
confidence 90% ¡ behavioral precision (á¸abáš)
Multi-Axis Trust Modeling â defines â ĘżAdÄlah
confidence 90% ¡ long-term integrity (ĘżadÄlah)
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:This paper proposes a Hadith-inspired multi-axis trust modeling framework, motivated by a structurally analogous problem in classical Hadith scholarship: assessing the trustworthiness of information sources using interpretable, multidimensional criteria rather than a single anomaly score. We translate five trust axes - long-term integrity (adalah), behavioral precision (dabt), contextual continuity (isnad), cumulative reputation, and anomaly evidence - into a compact set of 26 semantically meaningful behavioral features for user accounts. In addition, we introduce lightweight temporal features that capture short-horizon changes in these trust signals across consecutive activity windows. We evaluate the framework on the CLUE-LDS cloud activity dataset with injected account hijacking scenarios. On 23,094 sliding windows, a Random Forest trained on the trust features achieves near-perfect detection performance, substantially outperforming models based on raw event counts, minimal statistical baselines, and unsupervised anomaly detection. Temporal features provide modest but consistent gains on CLUE-LDS, confirming their compatibility with the static trust representation. To assess robustness under more challenging conditions, we further evaluate the approach on the CERT Insider Threat Test Dataset r6.2, which exhibits extreme class imbalance and sparse malicious behavior. On a 500-user CERT subset, temporal features improve ROC-AUC from 0.776 to 0.844. On a leakage-controlled 4,000-user configuration, temporal modeling yields a substantial and consistent improvement over static trust features alone (ROC-AUC 0.627 to 0.715; PR-AUC 0.072 to 0.264).
Tags
Links
- Source: https://arxiv.org/abs/2603.13246v1
- Canonical: https://arxiv.org/abs/2603.13246v1
Trouble viewing inline? Open PDF directly â
Full Text
64,973 characters extracted from source content.
Expand or collapse full text
Multi-Axis Trust Modeling for Interpretable Account Hijacking Detection Mohammad AL-Smadi Qatar University Doha, Qatar malsmadi@qu.edu.qa Abstract User and Entity Behavior Analytics (UEBA) systems aim to detect account hijacking by identifying deviations in user activity logs, yet many existing approaches rely on low-level count features and opaque models that limit interpretability for security analysts. This paper proposes a Hadith-inspired multi-axis trust modeling framework, motivated by a structurally analogous problem in classical Hadith scholarship: assessing the trustworthiness of information sources using interpretable, multi-dimensional criteria rather than a single anomaly score. We translate five trust axesâlong-term integrity (ĘżadÄlah), behavioral precision (á¸abáš), contextual continuity (isnÄd), cumulative reputation, and anomaly evidenceâinto a compact set of 26 semantically meaningful behavioral features for user accounts. In addition, we introduce lightweight temporal features that capture short-horizon changes in these trust signals across consecutive activity windows. We evaluate the framework on the CLUE-LDS cloud activity dataset with injected account hijacking scenarios. On 23,094 sliding windows, a Random Forest trained on the trust features achieves near-perfect detection performance (ROC-AUC â1.0â 1.0, PR-AUC â1.0â 1.0), substantially outperforming models based on raw event counts, minimal statistical baselines, and unsupervised anomaly detection. Temporal features provide modest but consistent gains on CLUE-LDS, confirming their compatibility with the static trust representation. To assess robustness under more challenging conditions, we further evaluate the approach on the CERT Insider Threat Test Dataset r6.2, which exhibits extreme class imbalance and sparse malicious behavior. On a 500-user CERT subset, temporal features improve ROC-AUC from 0.776 to 0.844. On a leakage-controlled 4,000-user configuration, temporal modeling yields a substantial and consistent improvement over static trust features alone (ROC-AUC 0.627 â 0.715; PR-AUC 0.072 â 0.264). These results show that Hadith-inspired trust axes provide an interpretable and effective foundation for UEBA, while temporal extensions improve robustness and scalability when individual behavioral windows are weak. Code and extracted features are provided publicly 111https://github.com/msmadi/UEBA. Keywords User and Entity Behavior Analytics (UEBA) â ¡ Account Hijacking Detection â ¡ Insider Threat Detection â ¡ Interpretable Machine Learning â ¡ Behavioral Feature Engineering â ¡ Temporal Behavior Modeling â ¡ Anomaly Detection â ¡ Security Analytics â ¡ Machine Learning for Security 1 Introduction Compromised user accounts remain a primary attack vector in cloud and enterprise environments. Adversaries who obtain valid credentials can perform actions that are syntactically legitimateâsuch as file access, sharing, or configuration changesâmaking malicious behavior difficult to distinguish from normal usage. User and Entity Behavior Analytics (UEBA) systems aim to address this challenge by learning behavioral profiles for users and detecting deviations that may indicate account hijacking or insider misuse [7]. A long-standing obstacle in UEBA research has been the lack of publicly available, realistic datasets. The release of the CLUE-LDS dataset marked an important advance by providing production-grade cloud storage logs spanning multiple years and thousands of users [7, 8]. CLUE-LDS was explicitly designed to support account-hijacking research through controlled synthetic attack injection. However, most existing approaches evaluated on CLUE-LDS either rely on high-dimensional event-count vectors with limited semantic meaning or adopt unsupervised clustering and anomaly detection methods whose outputs are difficult for security analysts to interpret [2]. In contrast to purely data-driven modeling, classical Hadith sciences in Islamic scholarship developed a rigorous and interpretable methodology for evaluating the trustworthiness of narrators. This disciplineâknown as Ężilm al-rijÄl (âthe science of narratorsâ)âassesses reliability along multiple dimensions, including moral integrity (ĘżadÄlah), precision and consistency in transmission (á¸abáš), and the continuity and soundness of transmission chains (isnÄd). Foundational works such as al-KhaášÄŤb al-BaghdÄdÄŤâs al-KifÄyah fÄŤ ĘżIlm al-RiwÄyah formalized these criteria, while the practice of jarḼ wa-taĘżdÄŤl documented cumulative reputational judgments issued by multiple scholars over time [1, 4, 5]. In addition, scholars developed methods for identifying subtle anomalies (shudhĹŤdh, Ężillah) that undermine apparent surface consistency. This multi-dimensional trust frameworkâintegrity, precision, chain continuity, reputation, and anomaly scrutinyâprovides a principled conceptual template for modern trust assessment. Drawing inspiration from these axes, we construct an interpretable behavioral representation for digital user accounts, enabling UEBA systems to reason about account trustworthiness in structured, semantically meaningful terms rather than opaque anomaly scores. Inspired by the analogy between Hadith narrators and digital user accountsâboth of which act as sources whose reliability must be inferred from observed behavior over timeâwe propose a Hadith-inspired multi-axis trust model for account hijacking detection. We operationalize five trust axes into a compact set of behavioral features that capture long-term stability, authentication hygiene, contextual continuity, accumulated reputation, and distributional anomalies. Our main contributions are as follows: 1. Conceptual framework: We introduce a Hadith-inspired multi-axis trust model that maps classical trust criteriaâĘżadÄlah, á¸abáš, isnÄd, reputation, and anomaly evidenceâonto user behavior analytics. 2. Feature engineering and ablation: We design a 26-dimensional interpretable feature set and conduct extensive ablation analysis to quantify the contribution of each trust axis. 3. Temporal trust modeling: We extend static trust features with 8 temporal summaries that capture short-horizon dynamics between consecutive windows. 4. Evaluation on CLUE-LDS: Using realistic hijack injection, we show that Hadith-inspired features substantially outperform raw-count and unsupervised baselines, achieving near-perfect discrimination in this setting. 5. Robustness analysis on CERT: We evaluate the same framework on the CERT r6.2 insider threat dataset and demonstrate that temporal trust features provide consistent improvements even when absolute performance is constrained by weak behavioral signals. 6. Interpretability: We provide feature- and axis-level importance analysis that explains detection decisions in analyst-friendly terms. We emphasize that we do not claim to formalize Hadith sciences themselves. Rather, we use their conceptual structure as a principled and interpretable template for trust assessment in digital identity systems. By evaluating the framework across both CLUE-LDS and CERT, we aim to clarify not only its strengths but also its limitations under increasingly realistic and challenging conditions. 2 Related Work 2.1 UEBA and the CLUE-LDS Dataset User and Entity Behavior Analytics (UEBA) systems aim to detect malicious or anomalous behaviorâsuch as account hijacking, insider threats, and data exfiltrationâby modeling deviations from a userâs historical activity profile. A long-standing challenge in UEBA research has been the scarcity of publicly available datasets that are both realistic and suitable for reproducible evaluation. Landauer et al. address this gap by introducing the CLUE-LDS dataset, which contains production-grade cloud storage logs spanning multiple years and thousands of users [7]. They demonstrate an account-hijacking scenario via synthetic user-switching and provide an initial anomaly detection baseline. Subsequent work by the same group and collaborators explores the statistical properties of log variables, automated field-type recognition, and dataset maintenance strategies to improve the quality and longevity of log-based intrusion detection benchmarks [17, 9]. Building on CLUE-LDS, Artioli et al. conduct a systematic comparison of clustering algorithms for UEBA and propose KATANA, an online k-means framework that aggregates event-level anomaly scores into day-level detection metrics [2, 3]. Their results highlight the practical trade-offs between sensitivity, stability, and computational efficiency in online UEBA systems. Collectively, these works identify several open challenges that remain largely unsolved: (1) producing anomaly scores that are interpretable by security analysts, (2) coping with extreme class imbalance where only a tiny fraction of activity is malicious, and (3) establishing general, reusable evaluation pipelines on public UEBA datasets that support both methodological comparison and reproducibility. 2.2 UEBA on CERT Insider Threat Datasets Despite the availability of CLUE-LDS, a substantial body of UEBA research continues to evaluate methods on the CERT Insider Threat datasets, particularly r6.2 [16, 18]. These datasets differ fundamentally from CLUE-LDS: malicious activity is sparse, distributed over long time horizons, and often weakly distinguishable from benign behavior at the level of individual events or short windows. Tuor et al. employ deep neural networks, including LSTMs, to model insider threat behavior on CERT and report ROC-AUC values below 0.90, reflecting the difficulty of the task [16]. Yuan et al. combine autoencoders with statistical profiling and similarly observe moderate detection performance [18]. Importantly, these lower scores are not indicative of weak modeling but rather of the inherent ambiguity and low signal-to-noise ratio in realistic insider threat data. As a result, CERT has become a de facto âstress-testâ dataset in the literature: methods that perform well on CERT are generally considered robust, while near-perfect performance is neither expected nor commonly reported [18]. This distinction is critical when interpreting results across datasets and motivates our evaluation on both CLUE-LDS (controlled, interpretable setting) and CERT (realistic, low-signal setting). 2.3 Trust Modeling and Hadith-Inspired Axes In classical Hadith sciences, the acceptance of a narration depends on a multi-dimensional assessment of narrators and transmission chains [1, 4, 5]. Core criteria include: ⢠ʿAdÄlah: moral integrity, long-term reliability, and avoidance of major violations. ⢠á¸abáš: precision, consistency, and care in transmission. ⢠IsnÄd: continuity and reliability of the chain of transmission (i.e., unbroken contextual linkage). ⢠JarḼ wa-TaĘżdÄŤl (reputation): accumulated positive or negative evaluations from multiple authorities over time. ⢠ShudhĹŤdh / ĘżIllah: identification of subtle anomalies, contradictions, or hidden defects. These criteria were operationalized through centuries of biographical evaluation and cross-verification, yielding an interpretable and structured trust framework. Although developed in a theological context, the underlying principlesâmulti-axis trust assessment, longitudinal evaluation, and anomaly scrutinyâare conceptually aligned with the goals of UEBA. We adopt these categories as an analogy to structure behavioral features for digital user accounts, without implying theological authority or equivalence. To our knowledge, this work represents the first systematic attempt to draw inspiration from Hadith scholarship for cyber-security analytics, and to translate its multi-dimensional trust logic into an interpretable feature-based UEBA framework. 3 Methodology 3.1 Problem Formulation We formulate account hijacking detection as a binary classification problem over fixed-size time windows of user activity. Each user u is associated with a time-ordered sequence of events (log entries), where each event records the timestamp, action type, and contextual metadata such as resource identifiers or network attributes. We segment each userâs event stream into overlapping windows (time-ordered batches of consecutive events) and assign each window a label: hijacked (y=1y=1) if any part of the window overlaps a malicious session, or normal (y=0y=0) otherwise. Formally, given a window WuW_u for user u, the goal is to learn a function fâ(Wu)f(W_u) that predicts whether the window corresponds to a hijacked account, based on features extracted from the window itself and, where applicable, from the userâs historical behavior prior to the window. This formulation naturally supports both static feature-based models and extensions to sequence-aware or temporal learning architectures. 3.2 Datasets and Preprocessing 3.2.1 CLUE-LDS Dataset We use the publicly released CLUE-LDS dataset from Zenodo (DOI: 10.5281/zenodo.7119953) [8]. The original dataset is a large JSON log in which each record contains fields such as id (event identifier), time (timestamp), uid (anonymized user ID), uidType (user name or IP address for logged-out users), type (event type), params (a dictionary of additional parameters such as file paths), and optional IP-related fields. For our experiments on CLUE-LDS, we sample a manageable but representative subset of the data and prepare it as follows: ⢠JSON to CSV: We stream-parse the JSON logs and write out a CSV with standardized columns user_id, timestamp, event_type, path, and ip_address. If an event lacks an IP address, we assign a synthetic âprimaryâ IP for that user (with occasional random deviations) to enable IP-based feature engineering while preserving anonymity. ⢠Filtering and sorting: We restrict analysis to the most active users to ensure sufficient historical context, convert timestamps to UTC, and sort all events by user and time. On the CLUE-LDS subset used in this paper, the logs span approximately 13 days (2017-07-07 to 2017-07-21) and include 500,000 events from 77 unique users, covering 24 distinct event types. Table 1 summarizes this subset. While CLUE-LDS enables controlled and interpretable evaluation, it represents a relatively favorable detection setting: user behavior is dense, logs are homogeneous, and injected hijacks introduce strong, localized deviations. In contrast, real-world insider threat datasets often exhibit sparse malicious activity, extreme class imbalance, and weak per-window signals. For this reason, many prior studies continue to rely on the CERT Insider Threat datasets despite their known challenges, using them as stress tests for behavioral detection models [11, 16, 18]. Reported performance on CERT r6.2 is typically substantially lower than on CLUE-LDS, reflecting the intrinsic difficulty of the task rather than methodological failure. Table 1: Summary of the CLUE-LDS subset used in this study Metric Value Total events 500,000 Number of users 77 Distinct event types 24 Time span 13 days (Jul 7â21, 2017) 3.2.2 CERT r6.2 Dataset To evaluate robustness under more realistic and lower-signal conditions, we also apply our framework to the CERT Insider Threat dataset (r6.2). Unlike CLUE-LDS, CERT contains sparse, long-horizon user activity with weak and often ambiguous malicious signals. Ground truth is available only at the user or scenario level, and malicious behavior may span months rather than short, well-defined intervals. For CERT, we adopt a temporal windowing strategy analogous to CLUE-LDS but adjust sampling to ensure balanced event exposure across users. We construct windows of fixed event length and label windows at the user level (i.e., all windows from documented malicious users are labeled positive). This setup reflects common practice in the CERT literature and avoids introducing artificially strong window-level leakage signals. As shown in our experiments, this results in substantially lowerâbut more realisticâdetection performance, consistent with prior work [16, 18]. 3.3 Synthetic Hijack Injection and Labeling (CLUE-LDS) Since CLUE-LDS contains normal (benign) user behavior, we inject realistic hijacking scenarios to create labeled anomalies, following the methodology proposed by Landauer et al. [7]. We identify users with sufficiently large event histories (at least 50 events) as candidates and simulate up to 30 hijack incidents on randomly selected users. For each selected user, we perform: 1. Hijack interval selection: Sample a random start time within the userâs activity period and define an 8-hour interval as the malicious session. 2. Pre-hijack signals: Insert 3â7 failed login attempts from unusual IP addresses shortly before the hijack start to mimic password guessing or alert-triggering behavior. 3. Hijack activity: During the hijack interval, inject a burst of suspicious actions using the datasetâs native event types (e.g., permission_changed, public_share_accessed), often at a typical hours. 4. IP anomaly: Modify source IP addresses during the hijack session to simulate access from different networks, including rapid IP switches that would be geographically implausible. We then slide a fixed-size window across each userâs timeline using a window size of 50 consecutive events and a step size of 25 events (50% overlap). A window is labeled as hijacked if its time range overlaps any injected hijack interval. This process yields 23,094 windows, of which 2,664 (11.5%) are labeled hijacked (class ratio â 1:7.7). 3.4 Hadith-Inspired Trust Axes and Feature Engineering We construct a base 26-dimensional feature vector for each window, structured along five Hadith-inspired axes. In extended experiments, we augment this representation with additional temporal features that capture window-to-window behavioral dynamics. Let W denote the current window for user u, and let HuH_u be the historical event sequence for u prior to W (i.e., all events before Wâs start time). As summarized in Table LABEL:tab:hadith-feature-computation, each axis yields a group of features as follows. Axis 1: ĘżAdÄlah (Integrity / Long-Term Stability) This axis reflects long-term consistency and reliability of the accountâs behavior: ⢠Active days: number of distinct days in HuH_u on which user u was active. ⢠Total events: total count of events in HuH_u. ⢠Account age: time (in days) from uâs first recorded event to the end of the current window. ⢠Daily consistency: standard deviation of per-day event counts in HuH_u (lower values indicate more regular daily activity). ⢠Average events per day: mean events per active day (|Hu||H_u| divided by active days). Users with longer, stable histories and regular activity patterns are expected to have higher ĘżadÄlah. Axis 2: Dabáš (Precision / Login Hygiene) This axis captures the userâs care and consistency in authentication and usage patterns: ⢠Login success rate: fraction of login attempts in the window that are successful (based on event types containing âloginâ). ⢠Delta failure rate: difference between the login failure rate in W and the userâs historical failure rate (captures sudden spikes in failed logins). ⢠Burstiness: maximum number of events by u that occur within any one-minute interval during the window (high burstiness may indicate scripted or automated activity). ⢠Out-of-hours fraction: proportion of events in W that occur outside uâs usual hours of activity (defined by the 2.5thâ97.5th percentile of uâs historical hour-of-day distribution). ⢠Timing entropy: entropy of the inter-event time gaps in W (a high entropy indicates irregular or erratic timing). ⢠Path novelty: fraction of resource paths in W that have never been observed in HuH_u. ⢠Sensitive action ratio: fraction of events in W that involve security-sensitive actions or objects (e.g., events or paths containing keywords like âadminâ, âdeleteâ, âshareâ). These features check if the window deviates from the userâs normal âhygieneâ profile in login and data access patterns. Axis 3: IsnÄd (Chain Continuity / Context) We treat IP addresses and network continuity as analogous to the reliability of a chain of narration: ⢠IP consistency: inverse of the number of distinct IP addresses observed in W (equals 1 if all events share a single IP, and lower as the IP count increases). ⢠Primary IP reuse: fraction of events in W that originate from uâs most-used historical IP address. ⢠Primary subnet reuse: fraction of events in W from uâs most-used /24 subnet (captures consistency in network location). ⢠Geo-impossible switches: fraction of consecutive events in W where the IP changes but the time gap is <5<5 minutes (implying impossible travel between geolocations). ⢠Session discontinuity: fraction of inter-event gaps in W that exceed 1 hour (many long gaps could indicate session breaks). ⢠New IP rate: fraction of IP addresses in W that have never appeared in HuH_u. Together, these six features form the isnÄd axis, capturing how seamlessly the context of activity carries over from the userâs historical profile. Axis 4: Reputation (JarḼ wa-TaĘżdÄŤl) This axis approximates the cumulative reputation of the user: ⢠History duration: total number of days spanned by HuH_u. ⢠Trust ratio: fraction of historically successful or allowed actions (e.g., login_successful, file_accessed) out of all pertinent attempts (successes + failures). ⢠Penalty rate: fraction of events in HuH_u that are failures or security-related alerts (e.g., access denied, error, policy violation). ⢠Behavior trend: difference between the failure rate in the first half vs. the second half of HuH_u (a large positive difference indicates improving behavior over time; negative indicates deteriorating behavior). Axis 5: Anomaly Evidence (ShudhĹŤdh / ĘżIllah) This axis quantifies deviations of the current window from the historical patterns: ⢠Event-type KL divergence: the KullbackâLeibler divergence between the distribution of event types in W and in HuH_u. ⢠Hour-of-day KL divergence: KL divergence between the distribution of event timestamps (by hour) in W versus HuH_u. ⢠Path novelty fraction: fraction of unique file or resource paths in W that do not appear in HuH_u. ⢠Event-type distance: Euclidean distance between the vector of event type counts in W and the average event type vector for uâs historical baseline. Axis 6: Temporal Extensions (Sequential Trust Dynamics) While the five axes above characterize behavior within an individual window relative to historical context, real account misuse often unfolds progressively over time. To capture such dynamics, we extend the Hadith-inspired framework with a set of temporal features computed over short sequences of adjacent windows for each user. These features explicitly model changes, trends, and accelerations in behavior, rather than static deviations alone. Temporal features are grouped according to their closest conceptual alignment with the original Hadith axes, yielding Temporal Dabáš and Temporal IsnÄd components. Temporal Dabáš (Precision Dynamics). These features capture how the userâs operational precision and hygiene evolve across consecutive windows: ⢠Burstiness change: difference in maximum per-minute activity between the current window and the immediately preceding window. ⢠Timing-entropy change: window-to-window difference in inter-event timing entropy, capturing sudden shifts in regularity. ⢠Login-failure acceleration: slope of login failure rate across recent windows, highlighting escalating authentication issues. ⢠Sensitive-action growth: short-term trend in the proportion of sensitive actions over successive windows. ⢠Activity volatility: rolling standard deviation of event counts across recent windows, reflecting instability in usage intensity. Temporal IsnÄd (Continuity Dynamics). These features model the stability of contextual chains (e.g., network context) over time: ⢠IP change rate: frequency of IP changes across consecutive windows. ⢠Primary-IP stability: fraction of recent windows dominated by the userâs historical primary IP. ⢠New-IP emergence velocity: rate at which previously unseen IP addresses appear over time. Temporal ĘżAdÄlah (Stability Dynamics). While static ĘżadÄlah captures long-term account stability, real-world accounts may exhibit gradual erosion or recovery of stability over time. To model this, we introduce temporal features that characterize changes in behavioral regularity across consecutive windows: ⢠Behavioral drift: divergence between recent and earlier window-level behavior profiles, capturing gradual deviation from baseline. ⢠Sequence entropy: entropy of short event-type sequences across windows, reflecting increasing randomness or loss of routine. ⢠Rare transition frequency: rate of uncommon event-type transitions over time, highlighting atypical operational flows. ⢠Run anomaly score: detection of unusually long or repetitive runs of similar actions, indicating abnormal persistence. ⢠N-gram transition anomaly: deviation of observed event n-grams from the userâs historical transition patterns. These features quantify whether a userâs overall behavioral stability is degrading over time, even when individual windows show only weak deviations. Temporal Reputation (Trust Trajectory). Reputation is inherently cumulative and temporal. To capture how trust signals accumulate or accelerate over time, we introduce a small set of temporal reputation features: ⢠Failure trend: slope of authentication or access failures across recent windows. ⢠Cumulative suspicious activity: running total of anomalous or policy-violating actions over time. ⢠Risk acceleration: second-order change in anomaly-related signals, capturing whether risk is increasing faster over time. In contrast to purely window-local features, these signals capture how trust evolves, rather than its absolute level at a single point in time. In our CERT r6.2 experiments, temporal reputation features contribute additional robustness under extreme class imbalance, where isolated anomalies are weak but sustained risk trajectories are informative. For comparison, we also construct a baseline alternative feature set, Raw counts: A 24-dimensional vector for each window in the CLUE-LDS and 16-dimensional in the CERT with the raw counts of each event type (using the 24 and 16 event types in the CLUE-LDS and CERT datasets as features). This baseline include little or no domain semantics and represent typical coarse feature sets in basic anomaly detection systems. 4 Experimental Setup 4.1 Training, Test, and Evaluation Protocol We split the 23,094 extracted windows into training (70%) and test (30%) subsets using stratified sampling to preserve the hijack ratio in each split. This results in 16,165 training windows (1,865 hijacked) and 6,929 test windows (799 hijacked). All reported test metrics are computed exclusively on the held-out test set. All feature sets (Hadith-inspired, raw event counts, and minimal statistical features) are standardized by subtracting the mean and scaling to unit variance using statistics computed on the training data only. The same scaling parameters are then applied to the test set to avoid information leakage. We evaluate a diverse set of supervised and unsupervised baselines in order to cover the dominant modeling paradigms used in prior UEBA research: 1. Hadith + Random Forest (RF): A random forest classifier with 100 trees, Gini impurity splitting, and balanced class weights. This model serves as our primary reference due to its strong performance on tabular data, robustness to feature scaling, and built-in interpretability via feature importance scores. 2. Raw Counts + RF: A random forest with identical hyperparameters to (1), trained on raw per-window event count vectors. This baseline reflects a common approach in log-based anomaly detection and isolates the effect of semantic feature engineering. 3. Isolation Forest (unsupervised): An Isolation Forest trained on the Hadith-inspired feature space with contamination set to the true anomaly rate. Anomaly scores are treated as detection statistics and thresholded only for reporting classification metrics. For all supervised models, we compute receiver operating characteristic (ROC) and precisionârecall (PR) curves on the test set and report the corresponding areas under the curves (ROC-AUC and PR-AUC). Given the strong class imbalance, we emphasize PR-AUC and F1 score as more informative indicators of detection quality. Precision, recall, and F1 are reported at the decision threshold that maximizes F1 on the test set; this threshold optimization is used solely for reporting and does not influence training or model selection. For the unsupervised Isolation Forest, ROC-AUC and PR-AUC are computed by treating the anomaly score as a continuous ranking statistic, consistent with prior anomaly detection literature. All models are implemented using scikit-learn [14]. 4.2 Evaluation Metrics on Imbalanced Data Account hijacking and insider threats are rare events, making naive metrics such as overall accuracy misleading. Prior work demonstrates that ROC curves can present an overly optimistic view of performance in highly imbalanced settings, whereas precisionârecall (PR) curves better reflect a modelâs ability to rank true anomalies ahead of false positives [6, 15]. Consequently, PR-AUC is widely recommended as a primary metric for anomaly detection and insider threat evaluation. Following best practices in the literature, we report ROC-AUC, PR-AUC, F1 score, precision, and recall, with particular emphasis on PR-AUC and F1 as indicators of operational usefulness under class imbalance [15]. 5 Results 5.1 Detection Performance Comparison â CLUE-LDS Table 2 summarizes detection performance on the CLUE-LDS dataset using a held-out test set of 6,929 windows, of which 762 correspond to injected hijacking activity. Overall, models based on Hadith-inspired trust features substantially outperform all baseline approaches across both ranking-oriented metrics (ROC-AUC, PR-AUC) and threshold-based classification metrics (F1, precision, recall). Table 2: Detection performance on CLUE-LDS (6,929 test windows, 762 hijacked). Temporal features provide strong complementary signals and remain highly discriminative even when used in isolation. Model ROC-AUC PR-AUC F1 Prec. / Rec. Original Hadith + RF 0.99997 0.99975 0.9948 0.993 / 0.996 Combined (Hadith+Temporal) + RF 0.99996 0.99963 0.9935 0.991 / 0.996 Temporal Only + RF 0.99989 0.99912 0.9869 0.986 / 0.988 Raw Counts + RF 0.98570 0.91691 0.8580 0.789 / 0.940 Isolation Forest 0.49358 0.10753 0.1996 0.111 / 0.990 The Original Hadith + RF model achieves near-perfect discrimination, with ROC-AUC exceeding 0.9999, PR-AUC exceeding 0.9997, and an F1 score of 0.9948 at 99.3% precision and 99.6% recall. These results indicate that, under the controlled hijack-injection setting of CLUE-LDS, the static Hadith-inspired trust features alone are sufficient to almost completely separate benign and hijacked activity windows using a relatively simple tree-based classifier. Augmenting the static trust representation with temporal features does not materially increase peak performance on CLUE-LDS. This reflects a saturation effect: the injected hijacking scenarios induce strong per-window behavioral deviations that are already captured by history-aware trust features. Nevertheless, temporal features remain highly informative. When used in isolation, temporal-only models achieve ROC-AUC above 0.999 and PR-AUC above 0.998, demonstrating that short-horizon behavioral dynamics encode independently discriminative signals. Feature-importance analysis further shows that temporal features contribute approximately 31% of the total importance in the combined model. Several temporal indicatorsâsuch as device transition anomalies, subnet drift, IP switching rate, and sequence entropyârank among the most informative predictors. This confirms that temporal features capture complementary structure that is not reducible to static window summaries, even when overall performance is already near saturation. In contrast, the strongest raw-feature baseline (Raw Counts + RF) achieves a respectable ROC-AUC of approximately 0.986 but suffers a substantial drop in PR-AUC (approximately 0.917) and F1 score (0.858). This gap highlights the limitations of frequency-based representations: while raw counts may rank anomalies reasonably well, they fail to capture the contextual and historical deviations required for high-precision detection under severe class imbalance. Unsupervised anomaly detection performs markedly worse. The Isolation Forest baseline achieves near-random PR-AUC, underscoring a recurring challenge in UEBA: without labeled examples or strong inductive biases, unsupervised methods struggle to distinguish true account hijacking from benign behavioral variation. Even a simple one-feature heuristic based on IP diversity substantially outperforms the unsupervised baseline, confirming that network instability is a strong signal in the injected attack scenarios. 5.2 Detection Performance Comparison â CERT r6.2 To assess robustness under a lower-signal insider-threat setting, we evaluate the same feature framework on the CERT r6.2 dataset. Compared to CLUE-LDS, CERT exhibits extreme class imbalance and sparse malicious activity, as presented in Table 3, making window-level discrimination substantially more difficult. We report results for (i) a 500-user subset (6,666 windows; 3.62% positive) and (i) a larger 4,000-user balanced configuration (22,622 windows; 1.07% positive), both using the same windowing scheme (50 events, step 25). Table 3: CERT r6.2 detection performance. CERT-500 uses 2,000 test windows (72 positive); CERT-4000 uses 6,787 test windows (72 positive). Temporal features provide a consistent lift over static Hadith axes and become more important in the larger, harder setting. Raw count features collapse to near-random performance on CERT, highlighting the need for structured and temporal trust modeling. Setting / Model ROC-AUC PR-AUC F1 Prec. / Rec. CERT-500 (500 users; 6,666 windows) Hadith Only + RF 0.7757 0.3479 0.3810 0.606 / 0.278 Temporal Only + RF 0.8088 0.3906 0.3972 0.406 / 0.389 Combined (Hadith+Temporal) + RF 0.8439 0.4989 0.5246 0.640 / 0.444 CERT-4000 Balanced (4,000 users; 22,622 windows) Hadith Only + RF 0.6267 0.0720 0.1132 0.176 / 0.083 Temporal Only + RF 0.7051 0.2300 0.3469 0.654 / 0.236 Combined (Hadith+Temporal) + RF 0.7151 0.2638 0.3529 0.600 / 0.250 Raw Counts + RF 0.4960 0.0408 0.0690 0.200 / 0.042 On the CERT-500 subset, temporal features yield a clear improvement over static trust modeling. The combined Hadith+Temporal model improves ROC-AUC from 0.7757 (Hadith-only) to 0.8439 (Combined+RF), and improves PR-AUC from 0.3479 to 0.4989. This indicates that short-horizon behavioral dynamics provide complementary signals beyond static historical deviations in this insider-threat setting. The CERT-4000 balanced configuration is substantially more challenging: positives constitute only 1.07% of windows and malicious behavior is sparse relative to the overall activity stream. Under this harder regime, static Hadith axes alone perform poorly (ROC-AUC 0.6267; PR-AUC 0.0720), while temporal-only features remain comparatively strong (ROC-AUC 0.7051; PR-AUC 0.2300). Combining static and temporal features yields the best overall ranking performance (ROC-AUC 0.7151; PR-AUC 0.2638), corresponding to a 14.1% relative improvement in ROC-AUC and a large gain in PR-AUC compared to the Hadith-only baseline. 5.3 Feature Importance and Ablation Study Analyzing random forest feature importances provides insight into which Hadith-inspired trust axes contribute most strongly to detection. We report importance patterns on both CLUE-LDS (account-hijacking simulation) and CERT r6.2 (labeled insider scenarios), which represent complementary evaluation regimes. On CLUE-LDS, the six isnÄd (IP-continuity) features account for roughly 70.3% of total importance, making network continuity the dominant axis under the injected hijack assumptions. The á¸abáš (precision and hygiene) features contribute approximately 16.8%, followed by anomaly evidence (6.5%), ĘżadÄlah (5.0%), and reputation (1.4%). This prominence aligns with operational intuition: abrupt changes in source IPs, subnets, or geographic plausibility are strong compromise indicators in the evaluated attack model. Although static trust features already saturate performance on CLUE-LDS, temporal features remain non-trivial: in the combined model, temporal features contribute approximately 31.3% of the total importance, and several temporal indicators (e.g., device transition anomaly, subnet drift, IP switching rate, and sequence entropy) rank among the top predictors. This suggests that temporal dynamics capture complementary structure even when overall performance is near saturation. On CERT, the importance profile shifts markedly. In both the 500-user and the 4,000-user balanced settings, temporal features contribute a substantial fraction of the combined modelâs importance (38.1% on CERT-500 and 43.6% on CERT-4000), indicating that sequential dynamics are more informative in low-signal, high-imbalance insider-threat regimes. The most informative features are no longer dominated by IP-continuity signals; instead, temporal transition irregularity emerges as a primary predictor. In particular, the top-ranked feature on both CERT settings is temp_kl_transition, which measures how strongly the windowâs event-transition structure deviates from the userâs historical transition profile. Table 4: Detailed ablation analysis on the CERT r6.2 (4,000 users) dataset. The full combined model achieves ROC-AUC = 0.7151. Î indicates the change relative to the full model. Setting Axis #Feat. ROC-AUC PR-AUC F1 ROC (A) Removing Individual Axes from Full Feature Set Remove ĘżAdÄlah 37 0.6993 0.2619 0.3696 â0.0158-0.0158 Remove á¸abáš 35 0.7216 0.1924 0.3232 +0.0065+0.0065 Remove IsnÄd 36 0.7185 0.2673 0.3542 +0.0034+0.0034 Remove Reputation 38 0.7140 0.2647 0.3579 â0.0012-0.0012 Remove Anomaly 38 0.7319 0.2553 0.3409 +0.0168+0.0168 Remove Temporalâá¸abáš 37 0.6278 0.0706 0.1185 â0.0873-0.0873 Remove TemporalâĘżAdÄlah 37 0.6981 0.2586 0.3448 â0.0170-0.0170 Remove TemporalâIsnÄd 39 0.6995 0.2718 0.3564 â0.0157-0.0157 Remove TemporalâReputation 39 0.6827 0.2644 0.3617 â0.0325-0.0325 (B) Single-Axis Only Models Only ĘżAdÄlah 5 0.5835 0.0710 0.1308 â0.1316-0.1316 Only á¸abáš 7 0.4849 0.0110 0.0260 â0.2302-0.2302 Only IsnÄd 6 0.5117 0.0524 0.0800 â0.2034-0.2034 Only Reputation 4 0.4859 0.0517 0.0800 â0.2292-0.2292 Only Anomaly 4 0.5067 0.0140 0.0263 â0.2084-0.2084 Only Temporalâá¸abáš 5 0.6637 0.2449 0.3960 â0.0515-0.0515 Only TemporalâĘżAdÄlah 5 0.5741 0.0384 0.1071 â0.1410-0.1410 Only TemporalâIsnÄd 3 0.5069 0.0244 0.0274 â0.2082-0.2082 Only TemporalâReputation 3 0.5000 0.0106 0.0210 â0.2151-0.2151 Axis-level ablation. Ablation results reinforce this dataset-dependent interpretation. On CLUE-LDS, removing isnÄd yields the largest degradation but does not collapse performance (PR-AUC decreases from 0.9996 to 0.9611), demonstrating that non-network trust axes capture independent behavioral deviations. On CERT-4000, the most critical axis is Temporal Dabáš: removing Temporal_Dabáš reduces ROC-AUC from 0.7151 to 0.6278, indicating that short-horizon behavioral precision dynamics are important when static trust cues are weak (see Table 4 for more results on the ablation study on CERT-4000). These results support two conclusions: First, the trust axes are complementary rather than redundant. Second, the relative importance of axes is strongly shaped by the dataset and threat model: CLUE-LDS hijack simulation amplifies network-continuity signals, whereas CERTâs sparse insider scenarios favor temporal transition and drift signals. This motivates reporting both datasets: CLUE-LDS illustrates an upper bound under strong compromise signals, while CERT stress-tests robustness under low-signal, operationally realistic conditions. 6 Discussion Our experiments reveal a sharp contrast between performance on CLUE-LDS and CERT r6.2, underscoring that UEBA effectiveness is strongly dataset- and threat-model dependent. On CLUE-LDS, which is explicitly designed for account-hijacking evaluation via synthetic session injection, hijacked activity induces strong, localized deviations from historical behavior. In this setting, the Hadith-inspired trust featuresâparticularly network-continuity (isnÄd) and precision (á¸abáš)âenable near-perfect separation between benign and malicious windows using simple classifiers. CERT represents a substantially more challenging scenario. Malicious behavior is rare, temporally diffuse, and often embedded within long periods of benign activity, with limited reliance on overt network anomalies. As a result, static trust features alone are insufficient. Across both the 500-user and 4,000-user CERT configurations, detection performance improves only when temporal features are introduced, yielding consistent gains in ROC-AUC, PR-AUC, and F1. This demonstrates that short-horizon behavioral drift and transition irregularities are important for realistic insider-threat detection. Feature-importance and ablation analyses further clarify this distinction. On CLUE-LDS, isnÄd-related features dominate, reflecting the assumption that hijacks cause abrupt IP and session changes. However, removing all IP-related features still preserves strong performance, indicating that the remaining trust axes capture independent behavioral signals. On CERT, temporal features contribute a much larger fraction of total importance, confirming that contextual evolution over time is more informative than instantaneous deviation in this setting. As noted in the insider-threat survey [18], many existing studies on the CERT dataset report that only a portion of insider activities can be detected reliably. In particular, the survey observes that roughly 80% of insider threats can be detected with relatively low error, while the remaining cases are much harder to identify as recall increases. This behavior is visible in the ROC curves reported by prior CERT-based studies, including Lin et al. [10], Liu et al. [12], Lu and Wong [13], and Yuan et al. [19]. In these works, false negatives rise quickly once detection performance moves beyond this moderate-recall range, indicating that some insider scenarios closely resemble normal user behavior. Our findings on CERT r6.2 follow the same pattern. When using only static behavioral features, detection performance remains limited, reflecting the difficulty of identifying the harder insider cases described in the survey. However, adding temporal trust features leads to consistent improvements in both ROC-AUC and PR-AUC. This suggests that modeling short-term behavioral changes and event sequences helps capture signals that are missed by static features alone, especially in the challenging detection regime highlighted by prior work. Moreover, most of these approaches rely on deep learning or complex ensemble models that operate as black boxes, offering limited insight into why a particular user or session is flagged as malicious. While such models can achieve strong performance on CERT scenarios, their lack of interpretability makes them difficult to validate, debug, and trust in operational security settings. Our findings also expose gaps in current UEBA research and evaluation. First, benchmark performance must be interpreted in light of implicit threat assumptions: synthetic hijacks can overstate achievable accuracy. Second, temporal trust degradation remains underexplored despite its clear impact in realistic insider settings. Finally, interpretability is often treated as secondary, yet our results show that semantically grounded features can deliver competitive performance without resorting to opaque models. Moreover, this work suggests that effective UEBA should focus not only on detecting deviations, but on modeling how trust evolvesâand degradesâover time, an aspect that current datasets and methods only partially capture. 7 Conclusion We presented a Hadith-inspired multi-axis trust framework for user and entity behavior analytics, translating classical trust criteria into an interpretable set of behavioral and temporal features for account hijacking detection. Across two public benchmarks with contrasting characteristics, our results show that semantically grounded trust axes substantially improve detection over raw count-based baselines. On CLUE-LDS, static trust features enable near-perfect separation under controlled hijack injection, while on the more challenging CERT dataset, temporal extensions provide significant and consistent gains in ROC-AUC, PR-AUC, and F1 score. Although CLUE-LDS serves as our primary benchmark for controlled evaluation and feature interpretability, the proposed Hadith-inspired trust framework is not specific to CLUE-LDS. The five trust axesâintegrity, precision, chain continuity, reputation, and anomaly evidenceâare defined in terms of generic properties of user behavior (timestamps, event semantics, authentication signals, and contextual metadata). These signals are commonly available in enterprise identity systems, cloud audit logs, security information and event management (SIEM) platforms, and application-level access logs. Consequently, our feature design is portable across datasets, and CLUE-LDS functions primarily as a reproducible benchmark rather than a limiting assumption. Beyond performance, the framework offers an interpretable structure that aligns machine learning decisions with analyst reasoning, supporting more transparent and actionable UEBA systems. As future work, our framework could be extended to incorporate explicit userâuser relationship modeling. Recent studies on the CERT r6.2 dataset show that combining graph neural networks with temporal models (e.g., GCNâBi-LSTM) can achieve higher AUC by capturing communication and collaboration structures among users [20]. The performance gap suggests that relational context is a missing signal in our current per-user trust representation. Integrating lightweight, interpretable graph-derived features into the Hadith-inspired trust axes offers a promising direction to improve detection while avoiding fully black-box models. Acknowledgments Generative AI tools were used in a limited and controlled manner during the development of this work. Specifically, Claude Sonnet 4.5 (Anthropic) was used to assist with software engineering tasks, including producing an initial code skeleton, refactoring, and improving code readability for the data loading, feature extraction, and experimental evaluation pipelines. This paper was edited for improving readability, clarity and organization of explanations using ChatGPT5.2. All research ideas, feature definitions, threat models, experimental design, data preprocessing logic, and evaluation protocols were conceived by the authors. All code produced with AI assistance was carefully reviewed, modified, and validated by the authors, and all experimental results were generated by author-executed code and independently verified through repeated runs, cross-validation, and ablation studies. No generative AI tools were used to generate data, labels, or experimental results, nor to make scientific or methodological decisions. References [1] a. al-BaghdÄdÄŤ (1987) Al-kifÄyah fÄŤ âilm al-riwÄyah. DÄr al-Kutub al-âIlmiyyah, Beirut. Note: Reprint of the Hyderabad edition Cited by: §1, §2.3. [2] P. Artioli, A. Maci, and A. MagrĂŹ (2024) A comprehensive investigation of clustering algorithms for user and entity behavior analytics. Frontiers in Big Data 7, p. 1375818. External Links: Document Cited by: §1, §2.1. [3] P. Artioli, A. MagrĂŹ, and P. Spalluto (2024) Account hijacking detection with KATANA: a k-means approach for targeted user behavior analysis. Note: Preprint (submitted to ITASEC 2024) Cited by: §2.1. [4] M. M. Azami (1978) Studies in early Hadith literature: with a critical edition of some early texts. American Trust Publications, Indianapolis. External Links: ISBN 9780891480017 Cited by: §1, §2.3. [5] J. A. C. Brown (2018) Hadith: muhammadâs legacy in the medieval and modern world. 2nd edition, Oneworld Publications, Oxford. External Links: ISBN 9781786075249 Cited by: §1, §2.3. [6] J. Davis and M. Goadrich (2006) The relationship between Precision-Recall and ROC curves. In Proc. 23rd Intl. Conf. on Machine Learning (ICML), p. 233â240. External Links: Document Cited by: §4.2. [7] M. Landauer, F. Skopik, G. HĂśld, and M. Wurzenberger (2022) A user and entity behavior analytics log data set for anomaly detection in cloud computing. In Proc. IEEE Intl. Conf. on Big Data (BDA4CID Workshop), p. 4285â4294. External Links: Document Cited by: §1, §1, §2.1, §3.3. [8] M. Landauer, F. Skopik, G. HĂśld, and M. Wurzenberger (2022) Cloud-based user entity behavior analytics log data set [data set]. Note: Zenodo Dataset External Links: Document Cited by: §1, §3.2.1. [9] M. Landauer, M. Wurzenberger, F. Skopik, and G. HĂśld (2022) Maintainable log datasets for evaluation of intrusion detection systems. Note: arXiv preprint arXiv:2203.08580 Cited by: §2.1. [10] L. Lin, S. Zhong, C. Jia, and K. Chen (2017) Insider threat detection based on deep belief network feature representation. In 2017 international conference on green informatics (ICGI), p. 54â59. Cited by: §6. [11] B. Lindauer and J. Glasser (2020) Insider threat test dataset. Note: KiltHubCommonly used as the CERT insider-threat benchmark; includes multiple scenarios such as r6.2. External Links: Document Cited by: §3.2.1. [12] L. Liu, O. De Vel, C. Chen, J. Zhang, and Y. Xiang (2018) Anomaly-based insider threat detection using deep autoencoders. In 2018 IEEE international conference on data mining workshops (ICDMW), p. 39â48. Cited by: §6. [13] J. Lu and R. K. Wong (2019) Insider threat detection with long short-term memory. In Proceedings of the Australasian Computer Science Week Multiconference, p. 1â10. Cited by: §6. [14] F. Pedregosa, G. Varoquaux, A. Gramfort, V. Michel, B. Thirion, O. Grisel, M. Blondel, P. Prettenhofer, R. Weiss, V. Dubourg, J. Vanderplas, A. Passos, D. Cournapeau, M. Brucher, M. Perrot, and Ă. Duchesnay (2011) Scikit-learn: machine learning in python. Journal of Machine Learning Research 12, p. 2825â2830. Cited by: §4.1. [15] T. Saito and M. Rehmsmeier (2015) The precision-recall plot is more informative than the ROC plot when evaluating binary classifiers on imbalanced datasets. PLOS ONE 10 (3), p. e0118432. External Links: Document Cited by: §4.2, §4.2. [16] A. Tuor, S. Kaplan, B. Hutchinson, N. Nichols, and S. Robinson (2017) Deep learning for unsupervised insider threat detection in structured cybersecurity data streams.. In AAAI Workshops, p. 224â231. Cited by: §2.2, §2.2, §3.2.1, §3.2.2. [17] M. Wurzenberger, G. HĂśld, M. Landauer, and F. Skopik (2024) Analysis of statistical properties of variables in log data for advanced anomaly detection in cyber security. Computers & Security 137, p. 103631. External Links: Document Cited by: §2.1. [18] S. Yuan and X. Wu (2021) Deep learning for insider threat detection: review, challenges and opportunities. Computers & Security 104, p. 102221. External Links: ISSN 0167-4048, Document, Link Cited by: §2.2, §2.2, §2.2, §3.2.1, §3.2.2, §6. [19] S. Yuan, P. Zheng, X. Wu, and Q. Li (2019) Insider threat detection via hierarchical neural temporal point processes. In 2019 IEEE international conference on big data (big data), p. 1343â1350. Cited by: §6. [20] R. Yumlembam, B. Issac, S. M. Jacob, L. Yang, and D. Krishnan (2025) Insider threat detection using gcn and bi-lstm with explicit and implicit graph representations. IEEE Transactions on Artificial Intelligence (), p. 1â12. External Links: Document Cited by: §7. Table 5: Summary of the Hadith-inspired trust axes and engineered features with explicit, code-level computation definitions. Axis Feature computation (derived from implementation) Integrity / Stability (ĘżAdÄlah) ⢠Active days: Number of distinct calendar dates with at least one historical event prior to the window start. ⢠Total events: Count of all user events before the window. ⢠Account age: Number of days between the userâs earliest historical event and the window end timestamp. ⢠Daily variability: Standard deviation of historical per-day event counts. ⢠Activity density: Historical total events divided by the number of historical active days. Precision / Hygiene (á¸abáš) ⢠Login success rate: Successful login/authentication events divided by total login/authentication attempts within the window. ⢠Failure delta: Difference between the login failure rate in the window and the historical login failure rate. ⢠Burstiness: Maximum number of events occurring within any single minute of the window. ⢠Out-of-hours fraction: Proportion of window events occurring outside the historical 2.5â97.5 percentile activity-hour range. ⢠Timing entropy: Shannon entropy of log-binned inter-event time gaps within the window. ⢠Path divergence: Fraction of unique resource paths in the window that were never observed in historical activity. ⢠Sensitive-action ratio: Proportion of window events whose event type or resource path contains sensitive-action keywords. Chain Continuity / Context (IsnÄd) ⢠IP consistency: Inverse of the number of distinct IP addresses observed in the window. ⢠Primary IP match: Fraction of window events whose IP matches the userâs most frequent historical IP. ⢠Subnet match: Fraction of window IPs belonging to the userâs dominant historical /24 subnet. ⢠Geo-impossible IP switches: Rate of IP changes occurring within less than five minutes. ⢠Session discontinuity: Fraction of consecutive inter-event gaps within the window that exceed one hour. ⢠New IP rate: Proportion of window IP addresses that have never appeared in the userâs history. Reputation (JarḼ wa-TaĘżdÄŤl) ⢠History duration: Total number of days spanned by the userâs historical activity. ⢠Trust ratio: Ratio of successful historical login/authentication events to total authentication attempts. ⢠Penalty rate: Fraction of historical events classified as failures. ⢠Failure trend: Difference between late-history and early-history authentication failure rates. Anomaly Evidence (ShudhĹŤdh / ĘżIllah) ⢠Event-type KL divergence: KullbackâLeibler divergence between window and historical event-type distributions. ⢠Hour-of-day KL divergence: KL divergence between window and historical hour-of-day activity distributions. ⢠Path novelty: Fraction of unique resource paths in the window that are absent from historical activity. ⢠Event-type L2 distance: Euclidean distance between window and historical event-type frequency vectors. Temporal Extensions (Sequence-Aware Trust Dynamics) Stability Dynamics (Temporal ĘżAdÄlah) ⢠Behavioral drift: JensenâShannon divergence between event-type distributions of consecutive windows. ⢠Sequence entropy: Shannon entropy of event-to-event transition probabilities within the window. ⢠Rare transition frequency: Fraction of event transitions whose historical probability falls below a rarity threshold. ⢠Run-length anomaly: Ratio between the longest run of identical consecutive events in the window and the expected historical run length. ⢠N-gram transition anomaly: KL divergence between window and historical n-gram event-sequence distributions. Precision Dynamics (Temporal á¸abáš) ⢠Timing regularity shift: Absolute difference in mean inter-event time between the current and previous window. ⢠Day-of-week divergence: KL divergence between window and historical weekday activity distributions. ⢠Activity rate drift: Difference in average event rate between consecutive windows. ⢠Authentication failure trend: Change in authentication failure rate between consecutive windows. ⢠Cumulative suspicious activity: Running accumulation of windows exhibiting suspicious behavioral indicators. Continuity Dynamics (Temporal IsnÄd) ⢠Subnet drift: Indicator of change in dominant IP subnet between consecutive windows. ⢠IP switch rate: Frequency of IP address changes normalized by window duration. ⢠Device transition anomaly: KL divergence between window and historical device-transition distributions. Reputation Dynamics (Temporal Reputation) ⢠Risk acceleration: Second-order difference of the inferred risk score across consecutive windows. ⢠Transition-distribution divergence: KL divergence between window-level and historical event-transition matrices. ⢠Activity autocorrelation: Temporal autocorrelation of activity rates across consecutive windows. Appendix A Complete Feature Formalization (42 Features) This appendix provides a complete mathematical formulation of the 42 engineered features summarized in Table LABEL:tab:hadith-feature-computation. A.1 Notation Let: ⢠U denote a user ⢠HU=e1,âŚ,enH_U=\e_1,âŚ,e_n\ denote all historical events of user U ⢠Wt=w1,âŚ,wmW_t=\w_1,âŚ,w_m\ denote the t-th sliding window ⢠tâ(e)t(e) denote the timestamp of event e ⢠dateâ(â )date(¡) extract the calendar date from a timestamp ⢠hâ(e)h(e) extract the hour-of-day from a timestamp ⢠Îâti=tâ(wi+1)âtâ(wi) t_i=t(w_i+1)-t(w_i) denote consecutive inter-event gaps ⢠â°E denote the set of event types ⢠P denote the set of resource paths ⢠âI denote the set of IP addresses ⢠âWtI_W_t, WtP_W_t denote IPs and paths observed in window WtW_t ⢠âHUI_H_U, HUP_H_U denote IPs and paths observed in history HUH_U ⢠IPâ(e)IP(e) denote the IP address of event e ⢠subnetâ(e)subnet(e) denote the /24 subnet of the IP address of event e ⢠IPUâIP^*_U denote the most frequent historical IP address of user U ⢠subnetUâsubnet^*_U denote the most frequent historical subnet of user U ⢠Loginâ(â )Login(¡) denote authentication attempts ⢠Successâ(â )Success(¡) denote successful authentication events ⢠Failâ(â )Fail(¡) denote failed authentication events ⢠Sensitiveâ(â )Sensitive(¡) denote events involving sensitive actions ⢠PXâ(â )P_X(¡) denote an empirical probability distribution estimated from set X ⢠Xv_X denote a normalized event-type frequency vector for set X ⢠Pâ(iâj)P(iâ j) denote the probability of event-type transition iâjiâ j ⢠TXT_X denote the event-transition probability matrix estimated from X ⢠PdowXP_dow^X denote the day-of-week distribution estimated from X ⢠PdeviceXP_device^X denote the device-type distribution estimated from X ⢠Q2.5,Q97.5Q_2.5,Q_97.5 denote the 2.5th and 97.5th percentiles of historical activity hours â˘ Ď denote a rarity threshold for transitions ⢠RtR_t denote the aggregate risk score at window t ⢠Rateâ(Wt)=|Wt|/ÎâTtRate(W_t)=|W_t|/ T_t denote the activity rate in window WtW_t ⢠Ͼξ denote a small constant to avoid division by zero A.2 Integrity / Stability (ĘżAdÄlah) ActiveDaysâ(U)=|dateâ(tâ(e)):eâHU|ActiveDays(U)= |\date(t(e)):eâ H_U\ | (1) TotalEventsâ(U)=|HU|TotalEvents(U)=|H_U| (2) AccountAgeâ(U,Wt)=maxwâWtâĄtâ(w)âmineâHUâĄtâ(e)AccountAge(U,W_t)= _wâ W_tt(w)- _eâ H_Ut(e) (3) DailyStdâ(U)=StdDevâĄ(|HUâ(d)|d)DailyStd(U)=StdDev (\|H_U(d)|\_d ) (4) EventsPerDayâ(U)=|HU|ActiveDaysâ(U)+ĎľEventsPerDay(U)= |H_U|ActiveDays(U)+Îľ (5) A.3 Precision / Hygiene (á¸abáš) LoginSuccessRateâ(Wt)=|Successâ(Wt)||Loginâ(Wt)|+ĎľLoginSuccessRate(W_t)= |Success(W_t)||Login(W_t)|+Îľ (6) ÎâFailRate=FailRateâ(Wt)âFailRateâ(HU) =FailRate(W_t)-FailRate(H_U) (7) Burstinessâ(Wt)=maxmâĄ|wâWt:âtâ(w)60â=m|Burstiness(W_t)= _m | \wâ W_t: t(w)60 =m \ | (8) OutOfHoursâ(Wt)=|wâWt:hâ(w)â[Q2.5,Q97.5]||Wt|OutOfHours(W_t)= |\wâ W_t:h(w)â[Q_2.5,Q_97.5]\||W_t| (9) TimingEntropyâ(Wt)=ââipiâlogâĄpiTimingEntropy(W_t)=- _ip_i p_i (10) PathDivergenceâ(Wt,HU)=|WtâHU||Wt|+ĎľPathDivergence(W_t,H_U)= |P_W_t _H_U||P_W_t|+Îľ (11) SensitiveRatioâ(Wt)=|Sensitiveâ(Wt)||Wt|SensitiveRatio(W_t)= |Sensitive(W_t)||W_t| (12) A.4 Chain Continuity / Context (IsnÄd) IPConsistencyâ(Wt)=1|âWt|+ĎľIPConsistency(W_t)= 1|I_W_t|+Îľ (13) PrimaryIPMatchâ(Wt)=|wâWt:IPâ(w)=IPUâ||Wt|PrimaryIPMatch(W_t)= |\wâ W_t:IP(w)=IP^*_U\||W_t| (14) SubnetMatchâ(Wt)=|wâWt:subnetâ(w)=subnetUâ||Wt|SubnetMatch(W_t)= |\wâ W_t:subnet(w)=subnet^*_U\||W_t| (15) GeoImpossibleâ(Wt)=|(wi,wi+1):Îâti<300â§IPâ(wi)â IPâ(wi+1)||Wt|GeoImpossible(W_t)= |\(w_i,w_i+1): t_i<300 (w_i) (w_i+1)\||W_t| (16) SessionDiscontinuityâ(Wt)=|Îâti>3600||Wt|SessionDiscontinuity(W_t)= |\ t_i>3600\||W_t| (17) NewIPRateâ(Wt,HU)=|âWtââHU||âWt|NewIPRate(W_t,H_U)= |I_W_t _H_U||I_W_t| (18) A.5 Reputation (JarḼ wa-TaĘżdÄŤl) HistoryDurationâ(U)=maxeâHUâĄtâ(e)âmineâHUâĄtâ(e)HistoryDuration(U)= _eâ H_Ut(e)- _eâ H_Ut(e) (19) TrustRatioâ(HU)=|Successâ(HU)||Loginâ(HU)|+ĎľTrustRatio(H_U)= |Success(H_U)||Login(H_U)|+Îľ (20) PenaltyRateâ(HU)=|Failâ(HU)||HU|PenaltyRate(H_U)= |Fail(H_U)||H_U| (21) FailureTrendâ(U)=FailRateâ(HUlate)âFailRateâ(HUearly)FailureTrend(U)=FailRate(H_U^late)-FailRate(H_U^early) (22) A.6 Anomaly Evidence (ShudhĹŤdh / ĘżIllah) DKL(Wt||HU)=âeââ°PWt(e)logPWtâ(e)PHUâ(e)D_KL(W_t||H_U)= _e P_W_t(e) P_W_t(e)P_H_U(e) (23) DKLhour(Wt||HU)=DKL(PhourWt||PhourHU)D_KL^hour(W_t||H_U)=D_KL(P_hour^W_t||P_hour^H_U) (24) PathNoveltyâ(Wt,HU)=|WtâHU||Wt|PathNovelty(W_t,H_U)= |P_W_t _H_U||P_W_t| (25) DLâ2â(Wt,HU)=âWtâHUâ2D_L2(W_t,H_U)=\|v_W_t-v_H_U\|_2 (26) A.7 Temporal Trust Dynamics (16) BehaviorDriftâ(t)=DJSâ(PWt,PWtâ1)BehaviorDrift(t)=D_JS(P_W_t,P_W_t-1) (27) SequenceEntropyâ(Wt)=ââi,jPâ(iâj)âlogâĄPâ(iâj)SequenceEntropy(W_t)=- _i,jP(iâ j) P(iâ j) (28) RareTransitionRateâ(Wt)=|(i,j):PUâ(iâj)<Ď||Wt|RareTransitionRate(W_t)= |\(i,j):P_U(iâ j)<Ď\||W_t| (29) RunLengthAnomalyâ(Wt)=maxâĄRunLengthâ(Wt)â[RunLengthâ(HU)]RunLengthAnomaly(W_t)= (W_t)E[RunLength(H_U)] (30) NGramAnomaly(Wt)=DKL(Pnâ-gramWt||Pnâ-gramHU)NGramAnomaly(W_t)=D_KL(P_n-gram^W_t||P_n-gram^H_U) (31) TimingShiftâ(t)=|ÎźÎâtWtâÎźÎâtWtâ1|TimingShift(t)=| _ t^W_t- _ t^W_t-1| (32) WeekdayDivergence(Wt)=DKL(PdowWt||PdowHU)WeekdayDivergence(W_t)=D_KL(P_dow^W_t||P_dow^H_U) (33) RateDriftâ(t)=Rateâ(Wt)âRateâ(Wtâ1)RateDrift(t)=Rate(W_t)-Rate(W_t-1) (34) FailureTrendâ(t)=FailRateâ(Wt)âFailRateâ(Wtâ1)FailureTrend(t)=FailRate(W_t)-FailRate(W_t-1) (35) CumulativeSuspiciousâ(t)=âk=1tâ[Suspiciousâ(Wk)]CumulativeSuspicious(t)= _k=1^tI[Suspicious(W_k)] (36) SubnetDriftâ(t)=â[subnettâ subnettâ1]SubnetDrift(t)=I[subnet_t _t-1] (37) IPSwitchRateâ(t)=|ÎâIP|ÎâtIPSwitchRate(t)= | | t (38) DeviceTransitionAnomaly(Wt)=DKL(PdeviceWt||PdeviceHU)DeviceTransitionAnomaly(W_t)=D_KL(P_device^W_t||P_device^H_U) (39) RiskAccelerationâ(t)=Rtâ2âRtâ1+Rtâ2RiskAcceleration(t)=R_t-2R_t-1+R_t-2 (40) TransitionKL(t)=DKL(TWt||THU)TransitionKL(t)=D_KL(T_W_t||T_H_U) (41) Autocorrelation=corrâĄ(Rateâ(Wt),Rateâ(Wtâ1))Autocorrelation=corr(Rate(W_t),Rate(W_t-1)) (42)