Toward an Insider Threat Detection Framework Using Honey Permissions

Toward an Insider Threat Detection Framework Using Honey Permissions
复制标题

使用 Honey 权限构建内部威胁检测框架

DOI:
10.22667/jisis.2015.08.31.019
复制
发表时间:
2015
期刊:
J. Internet Serv. Inf. Secur.
影响因子:
--
通讯作者:
Hassan Takabi
Hassan Takabi
中科院分区:
--
文献类型:
--
作者:
Parisa Kaghazgaran;Hassan Takabi

文献摘要

被引文献

相似文献

内部威胁仍然是计算机安全面临的最严重挑战之一。当授权用户滥用其权限并对组织造成损害时,就会发生内部攻击。欺骗技术已经作为内部威胁检测的常见解决方案,并且已经提出了几种技术,例如基于蜂蜜实体的方法。另一方面,访问控制系统缺乏检测内部威胁的能力。本文将欺骗技术引入到基于角色的访问控制(Role-Based Access Control,RBAC)模型中,这是目前应用最广泛的访问控制模型之一。我们引入了“蜂蜜权限”的概念,并利用它来扩展RBAC,以帮助进行内部威胁检测。我们将蜜糖权限定义为超出授权访问权限的权限,并将其分配给称为“候选角色”的角色子集。蜜糖权限中包含的对象是敏感对象的虚假版本,会引诱恶意用户。这样,就会检测到未经授权的用户试图访问敏感资源。我们对RBAC模型进行了扩展,增加了蜜糖权限,指示候选角色,并增加了监控单元,监控会话所有者激活候选角色子集并通过蜜糖权限访问对象的会话。我们提出了一种选择候选角色并为其分配蜜环权限的算法。此外,我们还提供了安全性分析,并考虑了可能会增加到RBAC系统进行评估的开销。
The insider threat remains one of the most serious challenges to computer security. An insider attack occurs when an authorized user misuses his privileges and causes damages to the organization. Deception techniques have served as a common solution to insider threat detection, and several techniques, such as approaches based on honey entities, have been proposed. On the other hand, access control systems lack the ability to detect insider threats. In this paper, we focus on integrating deception into the role-based access control (RBAC) model, which is one of the most widely used access control models. We introduce the notion of “honey permission” and use it to extend RBAC to help in insider threat detection. We define honey permissions as permissions that exceed the authorized access, and are assigned to a subset of roles known as “candidate roles”. Objects included in honey permissions are fake versions of sensitive objects that are enticing for malicious users. In this way, an attempt to access sensitive resources by unauthorized users would be detected. We extend the RBAC model by adding honey permissions, indicating candidate roles, and adding a monitoring unit which monitors the sessions in which the owners of the sessions activate a subset of candidate roles and have access to an object through a honey permission. We propose an algorithm to select candidate roles and assign honey permissions to them. Furthermore, we provide security analysis and consider the overhead that would be added to the RBAC system for evaluation.