A Multi-Tiered Framework for Insider Threat Prevention

被引:16
|
作者
Alsowail, Rakan A. [1 ]
Al-Shehari, Taher [1 ]
机构
[1] King Saud Univ, Riyadh 11362, Saudi Arabia
关键词
insider threat prevention; multi-tiered approach; information security; data privacy; ACCESS-CONTROL; INFORMATION;
D O I
10.3390/electronics10091005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As technologies are rapidly evolving and becoming a crucial part of our lives, security and privacy issues have been increasing significantly. Public and private organizations have highly confidential data, such as bank accounts, military and business secrets, etc. Currently, the competition between organizations is significantly higher than before, which triggers sensitive organizations to spend an excessive volume of their budget to keep their assets secured from potential threats. Insider threats are more dangerous than external ones, as insiders have a legitimate access to their organization's assets. Thus, previous approaches focused on some individual factors to address insider threat problems (e.g., technical profiling), but a broader integrative perspective is needed. In this paper, we propose a unified framework that incorporates various factors of the insider threat context (technical, psychological, behavioral and cognitive). The framework is based on a multi-tiered approach that encompasses pre, in and post-countermeasures to address insider threats in an all-encompassing perspective. It considers multiple factors that surround the lifespan of insiders' employment, from the pre-joining of insiders to an organization until after they leave. The framework is utilized on real-world insider threat cases. It is also compared with previous work to highlight how our framework extends and complements the existing frameworks. The real value of our framework is that it brings together the various aspects of insider threat problems based on real-world cases and relevant literature. This can therefore act as a platform for general understanding of insider threat problems, and pave the way to model a holistic insider threat prevention system.
引用
收藏
页数:29
相关论文
共 50 条
  • [41] The Herschel Multi-tiered Extragalactic Survey: HerMES
    Oliver, S. J.
    Bock, J.
    Altieri, B.
    Amblard, A.
    Arumugam, V.
    Aussel, H.
    Babbedge, T.
    Beelen, A.
    Bethermin, M.
    Blain, A.
    Boselli, A.
    Bridge, C.
    Brisbin, D.
    Buat, V.
    Burgarella, D.
    Castro-Rodriguez, N.
    Cava, A.
    Chania, P.
    Cirasuolo, M.
    Clements, D. L.
    Conley, A.
    Conversi, L.
    Cooray, A.
    Dowell, C. D.
    Dubois, E. N.
    Dwek, E.
    Dye, S.
    Eales, S.
    Elbaz, D.
    Farrah, D.
    Feltre, A.
    Ferrero, P.
    Fiolet, N.
    Fox, M.
    Franceschini, A.
    Gear, W.
    Giovannoli, E.
    Glenn, J.
    Gong, Y.
    Solares, E. A. Gonzalez
    Griffin, M.
    Halpern, M.
    Harwit, M.
    Hatziminaoglou, E.
    Heinis, S.
    Hurley, P.
    Hwang, H. S.
    Hyde, A.
    Ibar, E.
    Ilbert, O.
    MONTHLY NOTICES OF THE ROYAL ASTRONOMICAL SOCIETY, 2012, 424 (03) : 1614 - 1635
  • [42] A multi-tiered earthquake hazard model for Australia
    Brown, A
    Gibson, G
    TECTONOPHYSICS, 2004, 390 (1-4) : 25 - 43
  • [43] A multi-agent multi-tiered approach to information fusion
    Barker, Joseph
    Woodley, Robert
    Vincent, Gil
    Lindahl, Eric
    2007 INTERNATIONAL CONFERENCE ON INTEGRATION OF KNOWLEDGE INTENSIVE MULTI-AGENT SYSTEMS, 2007, : 216 - +
  • [44] Modern ransomware: Evolution, methodology, attack model, prevention and mitigation using multi-tiered approach
    Raj, Arpit
    Narayan, Vedant
    Muskan, Vivek
    Sani, Abhilash
    Sharma, Pankaj
    Sarma, S. S.
    SECURITY AND PRIVACY, 2024, 7 (06):
  • [45] Comparing two-tiered and multi-tiered grading approaches: students' perspectives
    Parsons, Carl
    Nguyen, Nga T.
    Joyce, Caroline
    JOURNAL OF FURTHER AND HIGHER EDUCATION, 2025,
  • [46] OS Independent and Hardware-Assisted Insider Threat Detection and Prevention Framework
    Erdin, Enes
    Aksu, Hidayet
    Uluagac, Selcuk
    Vai, Micheal
    Akkaya, Kemal
    2018 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM 2018), 2018, : 938 - 944
  • [47] Multi-tiered approach to monitoring measures network performance
    Sirkis, J
    Kersey, A
    LASER FOCUS WORLD, 2001, : 75 - +
  • [48] A MULTI-TIERED SCREENING SYSTEM FOR THE LEAST RESTRICTIVE SETTING
    ALLEN, RH
    WEINMAN, M
    LORIMOR, R
    CLAGHORN, JL
    AMERICAN JOURNAL OF PSYCHIATRY, 1980, 137 (08): : 968 - 971
  • [49] Required strength of geosynthetics in reinforced multi-tiered wall
    Zhang Fei
    Jia Shi-lin
    Zhu Yu-ming
    Lu Xiao-yi
    Shu Shuang
    ROCK AND SOIL MECHANICS, 2021, 42 (11) : 3079 - 3089
  • [50] MULTI-TIERED SAFETY FOR DYNAMIC AUTONOMOUS WAREHOUSE ROBOTS
    Rabb, Ethan
    Hagberg, Isaac
    Murphy, Alex
    Butts, Steven
    Guizani, Skander
    Rogers, John
    Heyman, Joseph L.
    Crews, Steven
    PROCEEDINGS OF ASME 2022 INTERNATIONAL MECHANICAL ENGINEERING CONGRESS AND EXPOSITION, IMECE2022, VOL 5, 2022,