Insider Threat Identification by Process Analysis
Insider Threat Identification by Process Analysis
复制标题
通过流程分析识别内部威胁
DOI:
10.1109/spw.2014.40
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
S. Peisert
中科院分区:
文献类型:
--
作者:
M. Bishop;H. Conboy;Huong Phan;Borislava I. Simidchieva;G. Avrunin;L. Clarke;L. Osterweil;S. Peisert
The insider threat is one of the most pernicious in computer security. Traditional approaches typically instrument systems with decoys or intrusion detection mechanisms to detect individuals who abuse their privileges (the quintessential "insider"). Such an attack requires that these agents have access to resources or data in order to corrupt or disclose them. In this work, we examine the application of process modeling and subsequent analyses to the insider problem. With process modeling, we first describe how a process works in formal terms. We then look at the agents who are carrying out particular tasks, perform different analyses to determine how the process can be compromised, and suggest countermeasures that can be incorporated into the process model to improve its resistance to insider attack.