An Insider Threat Detection Method Based on Business Process Mining

نویسندگان

  • Taiming Zhu
  • Yuanbo Guo
  • Ankang Ju
  • Jun Ma
  • Xu An Wang
چکیده

Currentintrusiondetectionsystemsaremostlyfordetectingexternalattacks,butthe“PrismDoor”and othersimilareventsindicatethatinternalstaffmaybringgreaterharmtoorganizationsininformation security.Traditional insider threatdetectionmethodsonlyconsider theaudit recordsofpersonal behaviorandfailedtocombineitwithbusinessactivities,whichmaymisstheinsiderthreathappened duringabusinessprocess.Theauthorsconsideroperators’behaviorandcorrectnessandperformance ofthebusinessactivities,proposeabusinessprocessminingbasedinsiderthreatdetectionsystem. Thesystemfirstlyestablishesthenormalprofilesofbusinessactivitiesandtheoperatorsbymining thebusinesslog,andthendetectsspecificanomaliesbycomparingthecontentofreal-timelogwith thecorrespondingnormalprofileinordertofindouttheinsidersandthethreatstheyhavebrought. Therelatinganomaliesaredefinedandthecorrespondingdetectionalgorithmsarepresented.The authorshaveperformedexperimentationusingtheProMframeworkandJavaprogramming,with fivesyntheticbusinesscases,andfoundthatthesystemcaneffectivelyidentifyanomaliesofboth operatorsandbusinessactivitiesthatmaybeindicativeofpotentialinsiderthreat. KeywoRDS Anomaly Detection, Insider Threat, Process Mining

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Evolving Insider Threat Detection Stream Mining Perspective

Evidence of malicious insider activity is often buried within large data streams, such as system logs accumulated over months or years. Ensemble-based stream mining leverages multiple classification models to achieve highly accurate anomaly detection in such streams, even when the stream is unbounded, evolving, and unlabeled. This makes the approach effective for identifying insider threats who...

متن کامل

Outlier Detection in Random Subspaces over Data Streams: An Approach for Insider Threat Detection

Insider threat detection is an emergent concern for industries and governments due to the growing number of attacks in recent years. Several Machine Learning (ML) approaches have been developed to detect insider threats, however, they still suffer from a high number of false alarms. None of those approaches addressed the insider threat problem from the perspective of stream mining data where a ...

متن کامل

Insider Threat Detection Using a Graph-Based Approach

The authors present the use of graph-based approaches to discovering anomalous instances of structural patterns in data that represent insider threat activity. The approaches presented search for activities that appear to match normal transactions, but in fact are structurally different. The authors show the usefulness of applying graph theoretic approaches to discovering suspicious insider act...

متن کامل

Frontiers in Insider Threats and Data Leakage Prevention

Organizations continue to be plagued by information leaks caused by insiders with legitimate access to critical or proprietary information. Such unauthorized leaks may result in significant damage to competitiveness, reputation and finances, and organizations should consider proactive approaches to preventing, detecting, and responding to this threat. In this special issue, we have selected eig...

متن کامل

Concept drift detection in business process logs using deep learning

Process mining provides a bridge between process modeling and analysis on the one hand and data mining on the other hand. Process mining aims at discovering, monitoring, and improving real processes by extracting knowledge from event logs. However, as most business processes change over time (e.g. the effects of new legislation, seasonal effects and etc.), traditional process mining techniques ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • IJBDCN

دوره 13  شماره 

صفحات  -

تاریخ انتشار 2017