A Risk Management Approach to the "Insider Threat"

A Risk Management Approach to the "Insider Threat"
复制标题

针对“内部威胁”的风险管理方法

DOI:
10.1007/978-1-4419-7133-3_6
复制
发表时间:
2010
影响因子:
1.5
通讯作者:
Sean Whalen
Sean Whalen
中科院分区:
医学4区
文献类型:
--
作者:
M. Bishop;S. Engle;D. Frincke;C. Gates;F. Greitzer;S. Peisert;Sean Whalen

文献摘要

被引文献

相似文献

最近的调查显示,由于内部入侵造成的财务影响和经营损失正在增加。但这些研究在什么是“内部人士”的问题上往往存在分歧;事实上,许多人只是隐式地定义它。理论上,适当选择和实施适当指定的安全策略应该可以防止合法用户滥用对计算机系统、信息和其他资源的访问。然而,即使可以精确地表达策略,安全策略的自然语言表达与该策略的表达之间的自然映射(以可以在计算机系统或网络上实现的形式)也会在执行中产生差距。本文根据这些漏洞精确地定义了“内部人员”,并探索了一种基于访问的模型,用于分析包括通常称为“内部人员”的威胁。该模型使组织能够根据资源及其包含的信息的业务价值对其资源进行排序。通过识别那些可以访问高价值资源的用户,我们获得了一个可以造成最大损害的有序用户列表。与此同时,我们检查心理指标,以确定哪些用户最容易不适当地使用。最后,我们研究了如何将该模型与取证日志和审计模型合并。
Recent surveys indicate that the financial impact and operating losses due to insider intrusions are increasing. But these studies often disagree on what constitutes an “insider;” indeed, manydefine it only implicitly. In theory, appropriate selection of, and enforcement of, properly specified security policies should prevent legitimate users from abusing their access to computer systems, information, and other resources. However, even if policies could be expressed precisely, the natural mapping between the natural language expression of a security policy, and the expression of that policyin a form that can be implemented on a computer system or network, createsgaps in enforcement. This paper defines “insider” precisely, in termsof thesegaps, andexploresan access-based modelfor analyzing threats that include those usually termed “insider threats.” This model enables an organization to order its resources based on thebusinessvalue for that resource andof the information it contains. By identifying those users with access to high-value resources, we obtain an ordered list of users who can cause the greatest amount of damage. Concurrently with this, we examine psychological indicators in order to determine which usersareatthe greatestriskofacting inappropriately. We concludebyexamining how to merge this model with one of forensic logging and auditing.