A Multi-Tiered Framework for Insider Threat Prevention

被引:16
|
作者
Alsowail, Rakan A. [1 ]
Al-Shehari, Taher [1 ]
机构
[1] King Saud Univ, Riyadh 11362, Saudi Arabia
关键词
insider threat prevention; multi-tiered approach; information security; data privacy; ACCESS-CONTROL; INFORMATION;
D O I
10.3390/electronics10091005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As technologies are rapidly evolving and becoming a crucial part of our lives, security and privacy issues have been increasing significantly. Public and private organizations have highly confidential data, such as bank accounts, military and business secrets, etc. Currently, the competition between organizations is significantly higher than before, which triggers sensitive organizations to spend an excessive volume of their budget to keep their assets secured from potential threats. Insider threats are more dangerous than external ones, as insiders have a legitimate access to their organization's assets. Thus, previous approaches focused on some individual factors to address insider threat problems (e.g., technical profiling), but a broader integrative perspective is needed. In this paper, we propose a unified framework that incorporates various factors of the insider threat context (technical, psychological, behavioral and cognitive). The framework is based on a multi-tiered approach that encompasses pre, in and post-countermeasures to address insider threats in an all-encompassing perspective. It considers multiple factors that surround the lifespan of insiders' employment, from the pre-joining of insiders to an organization until after they leave. The framework is utilized on real-world insider threat cases. It is also compared with previous work to highlight how our framework extends and complements the existing frameworks. The real value of our framework is that it brings together the various aspects of insider threat problems based on real-world cases and relevant literature. This can therefore act as a platform for general understanding of insider threat problems, and pave the way to model a holistic insider threat prevention system.
引用
收藏
页数:29
相关论文
共 50 条
  • [21] A Multi-tiered Model for Clinical Scholarship
    Julie B. Penzner
    Caitlin E. Snow
    Janna S. Gordon-Elliott
    Jon Avery
    Jimmy Avari
    Elizabeth L. Auchincloss
    George S. Alexopoulos
    Academic Psychiatry, 2018, 42 : 399 - 401
  • [22] A Multi-Tiered Approach to Family Engagement
    Bachman, Hadley F.
    Boone, Barbara J.
    EDUCATIONAL LEADERSHIP, 2022, 80 (01) : 58 - 62
  • [23] Multi-tiered control for undergraduate mechatronics
    Luecke, GR
    MECHATRONICS, 2002, 12 (02) : 311 - 321
  • [24] Regulation of imprinting: A multi-tiered process
    Rand, E
    Cedar, H
    JOURNAL OF CELLULAR BIOCHEMISTRY, 2003, 88 (02) : 400 - 407
  • [25] Roadmap for implementing a multi-tiered system of supports framework to improve school attendance
    Patricia A. Graczyk
    Christopher A. Kearney
    Current Psychology, 2024, 43 : 15286 - 15307
  • [26] Process Evaluation of Literacy Practices within a Multi-Tiered System of Supports Framework
    Morrison, Julie Q.
    Newman, Daniel S.
    Erickson, Amy Gaumer
    JOURNAL OF APPLIED SCHOOL PSYCHOLOGY, 2021, 37 (02) : 140 - 164
  • [27] Roadmap for implementing a multi-tiered system of supports framework to improve school attendance
    Graczyk, Patricia A.
    Kearney, Christopher A.
    CURRENT PSYCHOLOGY, 2024, 43 (17) : 15286 - 15307
  • [28] A Multi-tiered Storage Structure for Cloud Computing
    Chen, Hsin-Ya
    Lee, Pei-Yu
    Chang, Hsung-Pin
    2016 INTERNATIONAL COMPUTER SYMPOSIUM (ICS), 2016, : 636 - +
  • [29] The political economy of multi-tiered regulation in Europe
    Nicolaides, P
    JOURNAL OF COMMON MARKET STUDIES, 2004, 42 (03): : 599 - 618
  • [30] The design of a multi-tiered bus timetabling system
    Chun, HW
    Chan, SHC
    MULTIPLE APPROACHES TO INTELLIGENT SYSTEMS, PROCEEDINGS, 1999, 1611 : 771 - 779