首页> 外文会议>5th annual workshop on cyber security and information intelligence research 2009 >A Security Architecture to Protect against the Insider Threat from Damage, Fraud and Theft
【24h】

A Security Architecture to Protect against the Insider Threat from Damage, Fraud and Theft

机译:一种安全架构,可防止内部威胁免受损害,欺诈和盗窃

获取原文

摘要

The insider threat poses a significant and increasing problem for organizations. This is shown by the regular stories of fraud and data loss reported daily in the media in the US and elsewhere. There is a need to provide systematic protection from insider attacks because of their privileged access. We have developed a three-layer security architecture containing the physical, logical and social levels that we use to analyze the insider threat holistically to prevent, detect and recover from attacks. We examine destructive insider attacks, but the same analysis can be straightforwardly applied to the other main classes of insider threat from financial fraud and information theft. Our practical security model appears to have widespread application to other problem domains such as critical infrastructure and financial systems, as it allows the analysis of systems in their entirety including human and physical factors, not just as technical systems.
机译:内部威胁对组织构成了严重且日益严重的问题。美国和其他地区的媒体每天都会报道有关欺诈和数据丢失的常规报道,从而证明了这一点。由于特权访问,有必要提供针对内部攻击的系统保护。我们已经开发了一个三层安全体系结构,其中包含物理,逻辑和社会级别,我们可以使用这些级别来全面分析内部威胁,以防止,检测攻击并从攻击中恢复。我们研究了破坏性的内部人员攻击,但是相同的分析可以直接应用于其他主要类别的内部人员威胁,这些内部人员威胁来自金融欺诈和信息盗窃。我们的实用安全模型似乎已广泛应用于其他问题领域,例如关键基础结构和财务系统,因为它可以分析包括人为因素和物理因素在内的整个系统,而不仅仅是技术系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号