首页> 外文会议>2011 IEEE International System Conference >Dynamical System approach to insider threat detection
【24h】

Dynamical System approach to insider threat detection

机译:内幕威胁检测的动态系统方法

获取原文

摘要

Insider attacks have the potential to inflict severe damage to an organizations reputation, intellectual property and financial assets. The primary difference between the external intrusions and the insider intrusions is that an insider wields power of knowledge about the information system resources, their environment, policies. We present an approach to detecting abnormal behavior of an insider by applying Dynamical System Theory to the insiders computer usage pattern. This is because abnormal system usage pattern is one of the necessary precursors to actual execution of an attack. A base profile of system usage pattern for an insider is created via applying dynamical system theory measures. A continuous monitoring of the insiders system usage and its comparison with this base profile is performed to identify considerable deviations. A sample system usage in terms of application system calls is collected, analyzed, and graphical results of the analysis are presented. Our results indicate that dynamical system theory has the potential of detecting suspicious insider behavior occurring prior to the actual attack execution.
机译:内部人员攻击有可能严重损害组织的声誉,知识产权和金融资产。外部入侵与内部入侵之间的主要区别在于,内部入侵者掌握有关信息系统资源,其环境和策略的知识。我们提出了一种通过将动态系统理论应用于内部人员计算机使用模式来检测内部人员异常行为的方法。这是因为异常的系统使用模式是实际执行攻击的必要先决条件之一。通过应用动态系统理论方法,为内部人员创建系统使用模式的基本配置文件。对内部人员系统使用情况及其与该基本配置文件的比较进行连续监视,以识别明显的偏差。收集,分析了有关应用程序系统调用的示例系统用法,并提供了分析的图形结果。我们的结果表明,动力学系统理论具有检测实际攻击执行之前发生的可疑内部人行为的潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号