首页> 外文期刊>Future generation computer systems >Formal approach to thwart against insider attacks: A bio-inspired auto-resilient policy regulation framework
【24h】

Formal approach to thwart against insider attacks: A bio-inspired auto-resilient policy regulation framework

机译:反对内幕攻击的正式方法:生物启发的自动弹性政策监管框架

获取原文
获取原文并翻译 | 示例

摘要

The ever-growing number of cyber crimes and incidents (i.e., data breaches, privilege escalation, and masquerade attacks) indicates that traditional cyber defense mechanisms designed to manage access control and understand human behavioral intent are unable to protect large organizations against organized malicious attacks. The existing state-of-the-art solutions, extensively rely on human decision making and correlation-based analysis, to understand the anomalous intent of an insider. This consequently leads to data breaches, hence making insider threats one of the biggest challenges faced by the cybersecurity community today. To deal with these issues, new access control architectures and models must focus on the integration of threat analytics, auto-resiliency, and fast response time to mitigate an ongoing threat in a timely manner. In this article, to address these issues and limitations, we propose an integrated access control policy regulation framework, designed on biological principles. The proposed framework provides the ground to efficiently integrate Threat Analytics with Policy Regulation Mechanism against insider threats. Another major contribution of this article is to model access control policy regulation mechanism as an auto-regulatory state transition system, which could autonomously change its state (policy configuration) in real-time against an emergent insider threat. As the last step, with the help of formal methods, we rigorously verify, evaluate, and test the performance of our proposed systems on a real-life threat test dataset.
机译:越来越多的网络犯罪和事件(即,数据违规,特权升级和伪装攻击)表明,传统的网络防御机制旨在管理访问控制和理解人类行为意图无法保护大型组织免受有组织的恶意攻击。现有的最先进的解决方案,广泛地依靠人的决策和基于相关的分析,了解内幕的异常意图。因此,这导致数据泄露,因此提出内幕威胁到今天网络安全社区所面临的最大挑战之一。要处理这些问题,新的访问控制架构和模型必须专注于威胁分析,自动弹性和快速响应时间的集成来减轻持续的威胁。在本文中,为了解决这些问题和限制,我们提出了一个综合访问控制策略调节框架,用于生物原则。拟议的框架提供了与对内幕威胁的政策监管机制有效地整合威胁分析。本文的另一个主要贡献是将访问控制策略调节机制模拟为自动监管状态转换系统,这可以在实时地针对紧急内部威胁自主地改变其状态(策略配置)。作为最后一步,在正式方法的帮助下,我们严格验证,评估和测试我们所提出的系统在真实威胁测试数据集上的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号