A Multi-Tiered Framework for Insider Threat Prevention

被引:16
|
作者
Alsowail, Rakan A. [1 ]
Al-Shehari, Taher [1 ]
机构
[1] King Saud Univ, Riyadh 11362, Saudi Arabia
关键词
insider threat prevention; multi-tiered approach; information security; data privacy; ACCESS-CONTROL; INFORMATION;
D O I
10.3390/electronics10091005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As technologies are rapidly evolving and becoming a crucial part of our lives, security and privacy issues have been increasing significantly. Public and private organizations have highly confidential data, such as bank accounts, military and business secrets, etc. Currently, the competition between organizations is significantly higher than before, which triggers sensitive organizations to spend an excessive volume of their budget to keep their assets secured from potential threats. Insider threats are more dangerous than external ones, as insiders have a legitimate access to their organization's assets. Thus, previous approaches focused on some individual factors to address insider threat problems (e.g., technical profiling), but a broader integrative perspective is needed. In this paper, we propose a unified framework that incorporates various factors of the insider threat context (technical, psychological, behavioral and cognitive). The framework is based on a multi-tiered approach that encompasses pre, in and post-countermeasures to address insider threats in an all-encompassing perspective. It considers multiple factors that surround the lifespan of insiders' employment, from the pre-joining of insiders to an organization until after they leave. The framework is utilized on real-world insider threat cases. It is also compared with previous work to highlight how our framework extends and complements the existing frameworks. The real value of our framework is that it brings together the various aspects of insider threat problems based on real-world cases and relevant literature. This can therefore act as a platform for general understanding of insider threat problems, and pave the way to model a holistic insider threat prevention system.
引用
收藏
页数:29
相关论文
共 50 条
  • [31] Enforceability of Multi-Tiered Dispute Resolution Clauses
    Kayali, Didem
    JOURNAL OF INTERNATIONAL ARBITRATION, 2010, 27 (06): : 551 - 577
  • [32] A multi-tiered network with aerial and ground coverage
    Wu, Jie
    COMPUTER COMMUNICATIONS, 2018, 131 : 39 - 42
  • [33] A Multi-tiered Approach to Enterprise Support Services
    Chandersekaran, Coimbatore S.
    Simpson, William R.
    DESIGN, USER EXPERIENCE, AND USABILITY: THEORY, METHODS, TOOLS AND PRACTICE, PT 1, 2011, 6769 : 388 - 397
  • [34] DATA-DRIVEN DELIVERY OF IMPLEMENTATION SUPPORTS IN A MULTI-TIERED FRAMEWORK: A PILOT STUDY
    Sanetti, Lisa M. Hagermoser
    Collier-Meek, Melissa A.
    PSYCHOLOGY IN THE SCHOOLS, 2015, 52 (08) : 815 - 828
  • [36] Broadening Participation in Computing: The Multi-tiered Approach
    Johnson, Dalorion
    Wyss, J. Michael
    Gray, Jeff
    Daily, Shaundra
    Shih, Alan
    Abbot, Gypsy
    PROCEEDINGS OF THE 50TH ANNUAL ASSOCIATION FOR COMPUTING MACHINERY SOUTHEAST CONFERENCE, 2012,
  • [37] Delphi与Multi-tiered应用开发
    李剑宇
    周伟光
    唐利强
    杨兴萍
    湘潭师范学院学报(自然科学版), 2002, (03) : 41 - 44
  • [38] A multi-tiered classification scheme for component retrieval
    Smith, E
    Al-Yasiri, A
    Merabti, M
    24TH EUROMICRO CONFERENCE - PROCEEDING, VOLS 1 AND 2, 1998, : 882 - 889
  • [39] A Prefetching Scheme for Multi-tiered Storage Systems
    Chang, Hsung-Pin
    Chen, Chia-Yu
    Liu, Chien-Yi
    2018 IEEE SMARTWORLD, UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTING, SCALABLE COMPUTING & COMMUNICATIONS, CLOUD & BIG DATA COMPUTING, INTERNET OF PEOPLE AND SMART CITY INNOVATION (SMARTWORLD/SCALCOM/UIC/ATC/CBDCOM/IOP/SCI), 2018, : 1582 - 1586
  • [40] Multi-tiered playoffs and their impact on professional baseball
    Boronico, JS
    AMERICAN STATISTICIAN, 1999, 53 (01): : 56 - 61