Decoy Document Deployment for Effective Masquerade Attack Detection

Decoy Document Deployment for Effective Masquerade Attack Detection
复制标题

DOI:
10.1007/978-3-642-22424-9_3
复制
发表时间:
2011-07
期刊:
--
影响因子:
--
通讯作者:
M. B. Salem;S. Stolfo
M. B. Salem;S. Stolfo
中科院分区:
其他
文献类型:
--
作者:
M. B. Salem;S. Stolfo

文献摘要

被引文献

相似文献

伪装攻击带来了严重的安全问题,这是身份盗窃的结果。检测伪装者非常困难。之前的工作重点是分析合法用户行为并检测与正常行为的偏差,这些偏差可能预示着正在进行的伪装攻击。此类方法的误报率很高。其他工作研究了使用基于陷阱的机制作为检测一般内部攻击的手段。在本文中,我们研究了使用这种基于陷阱的机制来检测伪装攻击。我们评估部署在用户文件空间中的诱饵的所需属性以进行检测。我们通过两项用户研究调查了这些属性之间的权衡,并根据我们的用户研究结果提出了使用诱饵文档进行有效伪装检测的建议。
Masquerade attacks pose a grave security problem that is a consequence of identity theft. Detecting masqueraders is very hard. Prior work has focused on profiling legitimate user behavior and detecting deviations from that normal behavior that could potentially signal an ongoing masquerade attack. Such approaches suffer from high false positive rates. Other work investigated the use of trap-based mechanisms as a means for detecting insider attacks in general. In this paper, we investigate the use of such trap-based mechanisms for the detection of masquerade attacks. We evaluate the desirable properties of decoys deployed within a user’s file space for detection. We investigate the trade-offs between these properties through two user studies, and propose recommendations for effective masquerade detection using decoy documents based on findings from our user studies.