Insider threat detection using situation-aware MAS

Insider threat detection using situation-aware MAS
复制标题

使用态势感知 MAS 进行内部威胁检测

DOI:
--
复制
发表时间:
2008
期刊:
Fusion
影响因子:
--
通讯作者:
G. Jakobson
G. Jakobson
中科院分区:
--
文献类型:
--
作者:
J. Buford;L. Lewis;G. Jakobson

文献摘要

被引文献

相似文献

以前在自动化内部威胁检测方面的工作包括自顶向下的分析和来自网络和系统监视器的事件融合。态势感知可以扩展这类技术的能力,使其包括网络空间之外的可观察对象。由于以电子方式进行的不同类型的交易和社交网络的数量不断增加,以及监视能力的增强,情况管理对内部威胁的应用正变得越来越实用。基于我们早期在态势感知BDI代理中的工作,我们描述了用于内部威胁检测的分布式体系结构。此外,我们还考虑了使用基于代理的方法来模拟内部行为的示例,包括预期的和恶意的。这种方法提供了检测行为模式变化和错误信息活动的潜力。
Previous work in automating insider threat detection has included top-down analysis and fusion of events from network and system monitors. Situation-awareness can extend the capability of such techniques to include observables outside of cyber-space. The application of situation-management to insider threats is becoming more practical due to the growing volume of different types of transactions and social networking performed electronically as well as the increasing capability for surveillance. We describe our distributed architecture for insider threat detection based on our earlier work in situation-aware BDI agents. In addition we consider examples of using the agent-based approach to simulate insider behavior, both expected and malicious. This approach offers the potential of detecting changes in behavior patterns as well as mis-information activities.