The Danger Within: Insider Threat Modeling Using Business Process Models

被引:0
作者
von der Assen, Jan [1 ]
Hochuli, Jasmin [1 ]
Grubl, Thomas [1 ]
Stiller, Burkhard [1 ]
机构
[1] Univ Zurich UZH, Dept Informat, Commun Syst Grp, CH-8050 Zurich, Switzerland
来源
2024 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR | 2024年
关键词
Threat Modeling; Insider Threats; Risk Management; Business Process Modeling; BPMN;
D O I
10.1109/CSR61664.2024.10679492
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Threat modeling has been successfully applied to model technical threats within information systems. However, a lack of methods focusing on non-technical assets and their representation can be observed in theory and practice. Following the voices of industry practitioners, this paper explored how to model insider threats based on business process models. Hence, this study developed a novel insider threat knowledge base and a threat modeling application that leverages Business Process Modeling and Notation (BPMN). Finally, to understand how well the theoretic knowledge and its prototype translate into practice, the study conducted a real-world case study of an IT provider's business process and an experimental deployment for a real voting process. The results indicate that even without annotation, BPMN diagrams can be leveraged to automatically identify insider threats in an organization.
引用
收藏
页码:186 / 192
页数:7
相关论文
共 50 条
  • [31] Sensemaking in Dual Artefact Tasks - The Case of Business Process Models and Business Rules
    Chen, Tianwa
    Sadiq, Shazia
    Indulska, Marta
    CONCEPTUAL MODELING, ER 2020, 2020, 12400 : 105 - 118
  • [32] Multi-abstraction layered business process modeling
    Van Nuffel, Dieter
    De Backer, Manu
    COMPUTERS IN INDUSTRY, 2012, 63 (02) : 131 - 147
  • [33] A Segmented Abstraction Hierarchy Model for Business Process Modeling
    Jones, Arthur C.
    ADVANCES IN HUMAN FACTORS, BUSINESS MANAGEMENT, TRAINING AND EDUCATION, 2017, 498 : 127 - 133
  • [34] BUSINESS PROCESS MODELING: A WEBIBLIOMINIG PERSPECTIVE OF ARCHITECTURE FRAMEWORKS
    Oliveira, Gabriel Riso
    Ferreira, Ailton da Silva
    INDEPENDENT JOURNAL OF MANAGEMENT & PRODUCTION, 2019, 10 (03): : 1159 - 1183
  • [35] Verification of Common Business Rules in BPMN Process Models
    Rachdi, Anass
    En-Nouaary, Abdeslam
    Dahchour, Mohamed
    NETWORKED SYSTEMS, NETYS 2016, 2016, 9944 : 334 - 339
  • [36] Facilitating the comprehension of business process models for unexperienced modelers using token-based animations
    Maslov, Ilia
    Poelmans, Stephan
    INFORMATION & MANAGEMENT, 2024, 61 (05)
  • [37] A formal approach to modeling and verification of business process collaborations
    Corradini, Flavio
    Fornari, Fabrizio
    Polini, Andrea
    Re, Barbara
    Tiezzi, Francesco
    SCIENCE OF COMPUTER PROGRAMMING, 2018, 166 : 35 - 70
  • [38] VGPM: Using business process modeling for videogame modeling and code generation in multiple platforms
    Solis-Martinez, Jaime
    Pascual Espada, Jordan
    Garcia-Menendez, Natalia
    Pelayo G-Bustelo, B. Cristina
    Cueva Lovelle, Juan Manuel
    COMPUTER STANDARDS & INTERFACES, 2015, 42 : 42 - 52
  • [39] Structuring business objectives: A business process modeling perspective
    Neiger, D
    Churilov, L
    BUSINESS PROCESS MANAGEMENT, PROCEEDINGS, 2003, 2678 : 72 - 87
  • [40] An Approach for Improving Business Process Models Using Risk Analysis Techniques
    Lhannaoui, Hanane
    Kabbaj, Mohammed Issam
    Bakkoury, Zohra
    2014 SECOND WORLD CONFERENCE ON COMPLEX SYSTEMS (WCCS), 2014, : 94 - U760