首页> 外文期刊>Information management & computer security >Towards an insider threat prediction specification language
【24h】

Towards an insider threat prediction specification language

机译:迈向内部威胁预测规范语言

获取原文
获取原文并翻译 | 示例
           

摘要

Purpose - This paper presents the process of constructing a language tailored to describing insider threat incidents, for the purposes of mitigating threats originating from legitimate users in an IT infrastructure. Design/methodology/approach - Various information security surveys indicate that misuse by legitimate (insider) users has serious implications for the health of IT environments. A brief discussion of survey data and insider threat concepts is followed by an overview of existing research efforts to mitigate this particular problem. None of the existing insider threat mitigation frameworks provide facilities for systematically describing the elements of misuse incidents, and thus all threat mitigation frameworks could benefit from the existence of a domain specific language for describing legitimate user actions. Findings - The paper presents a language development methodology which centres upon ways to abstract the insider threat domain and approaches to encode the abstracted information into language semantics. The language construction methodology is based upon observed information security survey trends and the study of existing insider threat and intrusion specification frameworks. Originality/value - This paper summarizes the picture of the insider threat in IT infrastructures and provides a useful reference for insider threat modeling researchers by indicating ways to abstract insider threats.
机译:目的-本文介绍了一种构建用于描述内部威胁事件的语言的过程,目的是减轻来自IT基础架构中合法用户的威胁。设计/方法/方法-各种信息安全调查表明,合法(内部)用户的滥用严重影响了IT环境的健康。在对调查数据和内部威胁概念进行简要讨论之后,概述了为减轻这一特殊问题而进行的现有研究工作。现有的内部威胁缓解框架都没有提供系统地描述滥用事件要素的工具,因此,所有威胁缓解框架都可以从用于描述合法用户操作的领域特定语言中受益。调查结果-本文提出了一种语言开发方法论,该方法论着重于提取内部威胁域的方法以及将提取的信息编码为语言语义的方法。语言构建方法基于观察到的信息安全调查趋势以及对现有内部人员威胁和入侵规范框架的研究。原创性/价值-本文总结了IT基础架构中内部威胁的情况,并通过指出抽象内部威胁的方法为内部威胁建模研究人员提供了有用的参考。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号