【24h】

Towards insider threat detection using web server logs

机译:使用Web服务器日志进行内部威胁检测

获取原文

摘要

Malicious insiders represent one of the most difficult categories of threats an organization must consider when mitigating operational risk. Insiders by definition possess elevated privileges; have knowledge about control measures; and may be able to bypass security measures designed to prevent, detect, or react to unauthorized access. In this paper, we discuss our initial research efforts focused on the detection of malicious insiders who exploit internal organizational web servers. The objective of the research is to apply lessons learned in network monitoring domains and enterprise log management to investigate various approaches for detecting insider threat activities using standardized tools and a common event expression framework.
机译:恶意内部人称代表组织在减轻操作风险时必须考虑的最困难的威胁之一。根据定义的内部人士拥有升高的特权;了解控制措施;并且可以绕过旨在防止,检测或反应未经授权访问的安全措施。在本文中,我们讨论了我们的初步研究工作,专注于检测利用内部组织Web服务器的恶意内部人员的检测。该研究的目的是在网络监控域和企业日志管理中应用经验教训,以研究使用标准化工具和常见事件表达式框架检测内幕威胁活动的各种方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号