arrow
返回

A framework for understanding and predicting insider attacks

delete2002-10-01
delete198
PRE
AI
S
Schultz, EE *
DOI:10.1016/S0167-4048(02)01009-Xdelete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
In this paper an insider attack is considered to be deliberate misuse by those who are authorized to use computers and networks. Applying this definition in real-life settings to determine whether or not an attack was caused by an insider is often, however, anything but straightforward. We know very little about insider attacks, and misconceptions concerning insider attacks abound. The belief that most attacks come from inside is held by many information security professionals, for example, even though empirical statistics and firewaU togs indicate otherwise. This paper presents a framework based on previous studies and models of insider behavior as well as first-hand experience in dealing with insider attacks. This framework defines relevant types of insider attack-related behaviors and symptoms-indicators that include deliberate markers, meaningful errors, preparatory behaviors, correlated usage patterns, verbal behavior and personality traits. From these sets of indicators, clues can be pieced together to predict and detect an attack. The presence of numerous small clues necessitates the use of quantitative methods; multiple regression equations appear to be a particularly promising approach for quantifying prediction.
Keyword:
insider
insider attacks
insider attack prediction
insider attack detection
insider threat
attack indicators
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

暂无机构信息
引用论文

引用论文

暂无论文信息