Ben-ware: Identifying Anomalous Human Behaviour in Heterogeneous Systems Using Beneficial Intelligent Software

Ben-ware: Identifying Anomalous Human Behaviour in Heterogeneous Systems Using Beneficial Intelligent Software
复制标题

Ben-ware:使用有益的智能软件识别异构系统中的异常人类行为

DOI:
10.22667/jowua.2015.12.31.003
复制
发表时间:
2015
期刊:
J. Wirel. Mob. Networks Ubiquitous Comput. Dependable Appl.
影响因子:
--
通讯作者:
E. Ruck
E. Ruck
中科院分区:
--
文献类型:
--
作者:
A. Mcgough;B. Arief;Carl Gamble;David Wall;John Brennan;J. Fitzgerald;A. Moorsel;S. Alwis;G. Theodoropoulos;E. Ruck

文献摘要

被引文献

相似文献

内部威胁问题是任何组织都面临的一个重大且始终存在的问题。而当 可以建立安全机制,以减少外部代理访问 无论是窃取资产还是更改记录的系统,在应对内部威胁方面的问题要复杂得多。 如果员工已经拥有对系统的合法访问权限,则更难防止 防止他们实施不适当的行为,因为很难确定这些行为是否属于他们 是官方工作还是恶意的。在本文中,我们提出了“本软件”的概念:一个有益的 一种软件系统,使用从员工计算机收集的低级数据,以及人工 智能,用于识别员工的异常行为。通过比较每个员工的 违反他们自己的“正常”形象以及违反组织的规范的活动,我们可以 检测那些明显不同的可能表示恶意活动的内容。处理 误报是这里的主要挑战之一。异常行为可能表示恶意 活动(如员工试图窃取机密信息),但也可能是良性的 (例如,员工正在执行变通方法或选择捷径来完成其 工作)。因此,将误报的风险降到最低是很重要的,我们通过组合 在我们的方法中,来自人为因素、人工智能和风险分析的技术。开发 作为一个分布式系统,Ben-Ware具有三层体系结构,由(I)用于数据收集的探测器, (Ii)用于数据路由的中间节点,以及(Iii)用于数据分析的高级节点。这个 本软件的分布式特性允许对员工进行近乎实时的分析,而不需要 专用硬件或对现有基础设施造成重大影响。这将启用Ben-Ware 部署在因传统和低功率资源而受到限制的情况下,或者 在网络连接可能断断续续或带宽较低的情况下。我们展示了 本软件的适当性,无论是在其检测潜在恶意行为的能力方面,还是在其低影响方面 关于本组织的资源,通过概念验证系统和基于情景的 关于合成生成的用户数据。
The insider threat problem is a significant and ever present issue faced by any organisation. While security mechanisms can be put in place to reduce the chances of external agents gaining access to a system, either to steal assets or alter records, the issue is more complex in tackling insider threat. If an employee already has legitimate access rights to a system, it is much more difficult to prevent them from carrying out inappropriate acts, as it is hard to determine whether the acts are part of their official work or indeed malicious. We present in this paper the concept of “Ben-ware”: a beneficial software system that uses low-level data collection from employees’ computers, along with Artificial Intelligence, to identify anomalous behaviour of an employee. By comparing each employee’s activities against their own ‘normal’ profile, as well as against the organisational’s norm, we can detect those that are significantly divergent, which might indicate malicious activities. Dealing with false positives is one of the main challenges here. Anomalous behaviour could indicate malicious activities (such as an employee trying to steal confidential information), but they could also be benign (for example, an employee is carrying out a workaround or taking a shortcut to complete their job). Therefore it is important to minimise the risk of false positives, and we do this by combining techniques from human factors, artificial intelligence, and risk analysis in our approach. Developed as a distributed system, Ben-ware has a three-tier architecture composed of (i) probes for data collection, (ii) intermediate nodes for data routing, and (iii) high level nodes for data analysis. The distributed nature of Ben-ware allows for near-real-time analysis of employees without the need for dedicated hardware or a significant impact on the existing infrastructure. This will enable Ben-ware to be deployed in situations where there are restrictions due to legacy and low-power resources, or in cases where the network connection may be intermittent or has a low bandwidth. We demonstrate the appropriateness of Ben-ware, both in its ability to detect potentially malicious acts and its lowimpact on the resources of the organisation, through a proof-of-concept system and a scenario based on synthetically generated user data.