A Risk Management Approach to the "Insider Threat"
A Risk Management Approach to the "Insider Threat"
复制标题
针对“内部威胁”的风险管理方法
DOI:
10.1007/978-1-4419-7133-3_6
复制
发表时间:
2010
影响因子:
1.5
通讯作者:
Sean Whalen
中科院分区:
文献类型:
--
作者:
M. Bishop;S. Engle;D. Frincke;C. Gates;F. Greitzer;S. Peisert;Sean Whalen
Recent surveys indicate that the financial impact and operating losses due to insider intrusions are increasing. But these studies often disagree on what constitutes an “insider;” indeed, manydefine it only implicitly. In theory, appropriate selection of, and enforcement of, properly specified security policies should prevent legitimate users from abusing their access to computer systems, information, and other resources. However, even if policies could be expressed precisely, the natural mapping between the natural language expression of a security policy, and the expression of that policyin a form that can be implemented on a computer system or network, createsgaps in enforcement. This paper defines “insider” precisely, in termsof thesegaps, andexploresan access-based modelfor analyzing threats that include those usually termed “insider threats.” This model enables an organization to order its resources based on thebusinessvalue for that resource andof the information it contains. By identifying those users with access to high-value resources, we obtain an ordered list of users who can cause the greatest amount of damage. Concurrently with this, we examine psychological indicators in order to determine which usersareatthe greatestriskofacting inappropriately. We concludebyexamining how to merge this model with one of forensic logging and auditing.