• DocumentCode
    2128786
  • Title

    Detecting Insider Threats: A Trust-Aware Framework

  • Author

    Paci, Federica ; Fernandez-Gago, Carmen ; Moyano, Francisco

  • Author_Institution
    Dept. of Inf. Eng. & Comput. Sci., Univ. of Trento, Trento, Italy
  • fYear
    2013
  • fDate
    2-6 Sept. 2013
  • Firstpage
    121
  • Lastpage
    130
  • Abstract
    The number of insider threats hitting organizations and big enterprises is rapidly growing. Insider threats occur when trusted employees misuse their permissions on organizational assets. Since insider threats know the organization and its processes, very often they end up undetected. Therefore, there is a pressing need for organizations to adopt preventive mechanisms to defend against insider threats. In this paper, we propose a framework for insiders identification during the early requirement analysis of organizational settings and of its IT systems. The framework supports security engineers in the detection of insider threats and in the prioritization of them based on the risk they represent to the organization. To enable the automatic detection of insider threats, we extend the SI* requirement modeling language with an asset model and a trust model. The asset model allows associating security properties and sensitivity levels to assets. The trust model allows specifying the trust level that a user places in another user with respect to a given permission on an asset. The insider threats identification leverages the trust levels associated with the permissions assigned to users, as well as the sensitivity of the assets to which access is granted. We illustrate the approach based on a patient monitoring scenario.
  • Keywords
    business data processing; organisational aspects; personnel; specification languages; trusted computing; IT systems; SI* requirement modeling language; asset model; asset permission; asset sensitivity levels; big enterprises; insider threats detection; insider threats identification; insiders identification; organizational assets; organizations; preventive mechanisms; security engineers; security properties; trust model; trust-aware framework; trusted employees; Availability; Context; Drugs; Organizations; Security; Sensitivity; Silicon; insider threats; security requirements; trust relationships;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
  • Conference_Location
    Regensburg
  • Type

    conf

  • DOI
    10.1109/ARES.2013.22
  • Filename
    6657233