An Insider Threat Detection Method Based on Business Process Mining
نویسندگان
چکیده
Currentintrusiondetectionsystemsaremostlyfordetectingexternalattacks,butthe“PrismDoor”and othersimilareventsindicatethatinternalstaffmaybringgreaterharmtoorganizationsininformation security.Traditional insider threatdetectionmethodsonlyconsider theaudit recordsofpersonal behaviorandfailedtocombineitwithbusinessactivities,whichmaymisstheinsiderthreathappened duringabusinessprocess.Theauthorsconsideroperators’behaviorandcorrectnessandperformance ofthebusinessactivities,proposeabusinessprocessminingbasedinsiderthreatdetectionsystem. Thesystemfirstlyestablishesthenormalprofilesofbusinessactivitiesandtheoperatorsbymining thebusinesslog,andthendetectsspecificanomaliesbycomparingthecontentofreal-timelogwith thecorrespondingnormalprofileinordertofindouttheinsidersandthethreatstheyhavebrought. Therelatinganomaliesaredefinedandthecorrespondingdetectionalgorithmsarepresented.The authorshaveperformedexperimentationusingtheProMframeworkandJavaprogramming,with fivesyntheticbusinesscases,andfoundthatthesystemcaneffectivelyidentifyanomaliesofboth operatorsandbusinessactivitiesthatmaybeindicativeofpotentialinsiderthreat. KeywoRDS Anomaly Detection, Insider Threat, Process Mining
منابع مشابه
Evolving Insider Threat Detection Stream Mining Perspective
Evidence of malicious insider activity is often buried within large data streams, such as system logs accumulated over months or years. Ensemble-based stream mining leverages multiple classification models to achieve highly accurate anomaly detection in such streams, even when the stream is unbounded, evolving, and unlabeled. This makes the approach effective for identifying insider threats who...
متن کاملOutlier Detection in Random Subspaces over Data Streams: An Approach for Insider Threat Detection
Insider threat detection is an emergent concern for industries and governments due to the growing number of attacks in recent years. Several Machine Learning (ML) approaches have been developed to detect insider threats, however, they still suffer from a high number of false alarms. None of those approaches addressed the insider threat problem from the perspective of stream mining data where a ...
متن کاملInsider Threat Detection Using a Graph-Based Approach
The authors present the use of graph-based approaches to discovering anomalous instances of structural patterns in data that represent insider threat activity. The approaches presented search for activities that appear to match normal transactions, but in fact are structurally different. The authors show the usefulness of applying graph theoretic approaches to discovering suspicious insider act...
متن کاملFrontiers in Insider Threats and Data Leakage Prevention
Organizations continue to be plagued by information leaks caused by insiders with legitimate access to critical or proprietary information. Such unauthorized leaks may result in significant damage to competitiveness, reputation and finances, and organizations should consider proactive approaches to preventing, detecting, and responding to this threat. In this special issue, we have selected eig...
متن کاملConcept drift detection in business process logs using deep learning
Process mining provides a bridge between process modeling and analysis on the one hand and data mining on the other hand. Process mining aims at discovering, monitoring, and improving real processes by extracting knowledge from event logs. However, as most business processes change over time (e.g. the effects of new legislation, seasonal effects and etc.), traditional process mining techniques ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- IJBDCN
دوره 13 شماره
صفحات -
تاریخ انتشار 2017