The Danger Within: Insider Threat Modeling Using Business Process Models

被引:0
作者
von der Assen, Jan [1 ]
Hochuli, Jasmin [1 ]
Grubl, Thomas [1 ]
Stiller, Burkhard [1 ]
机构
[1] Univ Zurich UZH, Dept Informat, Commun Syst Grp, CH-8050 Zurich, Switzerland
来源
2024 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR | 2024年
关键词
Threat Modeling; Insider Threats; Risk Management; Business Process Modeling; BPMN;
D O I
10.1109/CSR61664.2024.10679492
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Threat modeling has been successfully applied to model technical threats within information systems. However, a lack of methods focusing on non-technical assets and their representation can be observed in theory and practice. Following the voices of industry practitioners, this paper explored how to model insider threats based on business process models. Hence, this study developed a novel insider threat knowledge base and a threat modeling application that leverages Business Process Modeling and Notation (BPMN). Finally, to understand how well the theoretic knowledge and its prototype translate into practice, the study conducted a real-world case study of an IT provider's business process and an experimental deployment for a real voting process. The results indicate that even without annotation, BPMN diagrams can be leveraged to automatically identify insider threats in an organization.
引用
收藏
页码:186 / 192
页数:7
相关论文
共 50 条
  • [21] Analysis of Business Process Batching Using Causal Event Models
    Waibel, Philipp
    Novak, Christian
    Bala, Saimir
    Revoredo, Kate
    Mendling, Jan
    PROCESS MINING WORKSHOPS, ICPM 2020 INTERNATIONAL WORKSHOPS, 2021, 406 : 17 - 29
  • [22] From Business Process Models to Use Case Models: A Systematic Approach
    Cruz, Estrela Ferreira
    Machado, Ricardo J.
    Santos, Maribel Yasmina
    ADVANCES IN ENTERPRISE ENGINEERING VIII, 2014, 174 : 167 - 181
  • [23] Modeling Business Objectives for Business Process Management
    Lohrmann, Nilatthias
    Reichert, Manfred
    S-BPM ONE - SCIENTIFIC RESEARCH, 2012, 104 : 106 - 126
  • [24] From Business Process Models to Process-Oriented Software Systems
    Ouyang, Chun
    Dumas, Marlon
    Van der Aalst, Wil M. P.
    Ter Hofstede, Arthur H. M.
    Mendling, Jan
    ACM TRANSACTIONS ON SOFTWARE ENGINEERING AND METHODOLOGY, 2009, 19 (01) : 1 - 37
  • [25] Aligning Business Process Models and Domain Knowledge: A Meta-modeling Approach
    Cherfi, Samira Si-Said
    Ayad, Sarah
    Comyn-Wattiau, Isabelle
    ADVANCES IN DATABASES AND INFORMATION SYSTEMS, 2013, 186 : 45 - 56
  • [26] Levels of Business Process Modeling
    Tomaskova, Hana
    VISION 2020: SUSTAINABLE ECONOMIC DEVELOPMENT, INNOVATION MANAGEMENT, AND GLOBAL GROWTH, VOLS I-IX, 2017, 2017, : 3495 - 3498
  • [27] Business Process Modeling with URN
    Weiss, Michael
    Amyot, Daniel
    INTERNATIONAL JOURNAL OF E-BUSINESS RESEARCH, 2005, 1 (03) : 63 - 90
  • [28] Business Process Modeling: A Survey
    He, Gang
    Xue, Gang
    Yao, Shaowen
    Wu, Zhongwei
    PROCEEDINGS OF ANNUAL CONFERENCE OF CHINA INSTITUTE OF COMMUNICATIONS, 2010, : 172 - +
  • [29] REGULATED BUSINESS PROCESS MODELING
    Svatos, Oleg
    CONFENIS-2013: 7TH INTERNATIONAL CONFERENCE ON RESEARCH AND PRACTICAL ISSUES OF ENTERPRISE INFORMATION SYSTEMS, 2013, 41 : 73 - 88
  • [30] THE CIMOSA BUSINESS MODELING PROCESS
    ZELM, M
    VERNADAT, FB
    KOSANKE, K
    COMPUTERS IN INDUSTRY, 1995, 27 (02) : 123 - 142