首页> 外文会议>International Conference on Enterprise Information Systems >PROACTIVE INSIDER-THREAT DETECTION Against Confidentiality in Sensitive Pervasive Applications
【24h】

PROACTIVE INSIDER-THREAT DETECTION Against Confidentiality in Sensitive Pervasive Applications

机译:主动内在威胁威胁检测敏感普遍应用中的机密性

获取原文

摘要

The primary objective of this research is to mitigate insider threats against sensitive information stored in an organization's computer system, using dynamic forensic mechanisms to detect insiders' malicious activities. Among various types of insider threats, which may break confidentiality, integrity, or availability, this research is focused on the violations of confidentiality with privilege misuse or escalation in sensitive applications. We identify insider-threat scenarios and then describe how to detect each threat scenario by analyzing the primitive user activities, we implement our detection mechanisms by extending the capabilities of existing software packages. Since our approach can proactively detect the insider's malicious behaviors before the malicious action is finished, we can prevent the possible damage proactively. In this particular paper the primary sources for our implementation are from the Windows file system activities, the Windows Registry, the Windows Clipboard system, and printer event logs and reports. However, we believe our approaches for countering insider threats can be also applied to other computing environments.
机译:本研究的主要目标是利用动态取证机制减轻存储在组织计算机系统中的敏感信息的内幕威胁来检测企业的恶意活动。在各种类型的内幕威胁中,这可能会破坏机密性,完整性或可用性,这项研究专注于违反敏感应用中的特权滥用或升级的机密性。我们识别内部威胁方案,然后通过分析原始用户活动来介绍如何检测每个威胁方案,我们通过扩展现有软件包的功能来实现我们的检测机制。由于我们的方法可以在恶意行动完成之前主动地检测内幕的恶意行为,因此我们可以自主地防止可能的损坏。在此特定文件中,我们实现的主要来源来自Windows文件系统活动,Windows注册表,Windows剪贴板系统和打印机事件日志和报告。但是,我们认为我们的反击内部威胁的方法也可以应用于其他计算环境。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号