Multi-Domain Information Fusion for Insider Threat Detection

被引:60
作者
Eldardiry, Hoda [1 ]
Bart, Evgeniy [1 ]
Liu, Juan [1 ]
Hanley, John [1 ]
Price, Bob [1 ]
Brdiczka, Oliver [1 ]
机构
[1] Xerox Corp, Palo Alto Res Ctr, Palo Alto, CA 94304 USA
来源
IEEE CS SECURITY AND PRIVACY WORKSHOPS (SPW 2013) | 2013年
关键词
Insider threat detection; anomaly detection; information fusion;
D O I
10.1109/SPW.2013.14
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Malicious insiders pose significant threats to information security, and yet the capability of detecting malicious insiders is very limited. Insider threat detection is known to be a difficult problem, presenting many research challenges. In this paper we report our effort on detecting malicious insiders from large amounts of work practice data. We propose novel approaches to detect two types of insider activities: (1) blend-in anomalies, where malicious insiders try to behave similar to a group they do not belong to, and (2) unusual change anomalies, where malicious insiders exhibit changes in their behavior that are dissimilar to their peers' behavioral changes. Our first contribution focuses on detecting blend-in malicious insiders. We propose a novel approach by examining various activity domains, and detecting behavioral inconsistencies across these domains. Our second contribution is a method for detecting insiders with unusual changes in behavior. The key strength of this proposed approach is that it avoids flagging common changes that can be mistakenly detected by typical temporal anomaly detection mechanisms. Our third contribution is a method that combines anomaly indicators from multiple sources of information.
引用
收藏
页码:45 / 51
页数:7
相关论文
共 18 条
[1]  
[Anonymous], 2018, Social stratification
[2]  
Band S., CMUSEI2006TR
[3]  
Bowen B., 2009, SECURECOMM 2009
[4]  
Bradford P., 2005, ACSAC
[5]  
CARLEY KM, 2003, 8 INT COMM CONTR RES
[6]  
Eldardiry H., 2012, 21 ACM INT C INF KNO
[7]  
Herbig K., 2002, 025 PERSERCE
[8]  
Herbig K., 2008, 0805 DEP DEF
[9]  
Keeney Michelle., INSIDER THREAT STUDY
[10]  
Lanxoma, INT DESKT SURV