Insider Threat Identification by Process Analysis

Insider Threat Identification by Process Analysis
复制标题

通过流程分析识别内部威胁

DOI:
10.1109/spw.2014.40
复制
发表时间:
2014
期刊:
2014 IEEE Security and Privacy Workshops
影响因子:
--
通讯作者:
S. Peisert
S. Peisert
中科院分区:
--
文献类型:
--
作者:
M. Bishop;H. Conboy;Huong Phan;Borislava I. Simidchieva;G. Avrunin;L. Clarke;L. Osterweil;S. Peisert

文献摘要

被引文献

相似文献

内部威胁是计算机安全中最有害的威胁之一。传统方法通常使用诱饵或入侵检测机制来检测系统,以检测滥用特权的个人(典型的“内部人员”)。此类攻击要求这些代理能够访问资源或数据,以便破坏或泄露它们。在这项工作中,我们研究了流程建模的应用以及对内部问题的后续分析。通过流程建模,我们首先以正式术语描述流程如何工作。然后,我们查看正在执行特定任务的代理,执行不同的分析以确定流程如何受到损害,并提出可以纳入流程模型的对策,以提高其对内部攻击的抵抗力。
The insider threat is one of the most pernicious in computer security. Traditional approaches typically instrument systems with decoys or intrusion detection mechanisms to detect individuals who abuse their privileges (the quintessential "insider"). Such an attack requires that these agents have access to resources or data in order to corrupt or disclose them. In this work, we examine the application of process modeling and subsequent analyses to the insider problem. With process modeling, we first describe how a process works in formal terms. We then look at the agents who are carrying out particular tasks, perform different analyses to determine how the process can be compromised, and suggest countermeasures that can be incorporated into the process model to improve its resistance to insider attack.