DocumentCode
3681556
Title
Visualizing the insider threat: challenges and tools for identifying malicious user activity
Author
Philip A. Legg
Author_Institution
Department of Computer Science and Creative Technologies, University of the West of England, Bristol, UK
fYear
2015
Firstpage
1
Lastpage
7
Abstract
One of the greatest challenges for managing organisational cyber security is the threat that comes from those who operate within the organisation. With entitled access and knowledge of organisational processes, insiders who choose to attack have the potential to cause serious impact, such as financial loss, reputational damage, and in severe cases, could even threaten the existence of the organisation. Security analysts therefore require sophisticated tools that allow them to explore and identify user activity that could be indicative of an imminent threat to the organisation. In this work, we discuss the challenges associated with identifying insider threat activity, along with the tools that can help to combat this problem. We present a visual analytics approach that incorporates multiple views, including a user selection tool that indicates anomalous behaviour, an interactive Principal Component Analysis (iPCA) tool that aids the analyst to assess the reasoning behind the anomaly detection results, and an activity plot that visualizes user and role activity over time. We demonstrate our approach using the Carnegie Mellon University CERT Insider Threat Dataset to show how the visual analytics workflow supports the Information-Seeking mantra.
Keywords
"Visual analytics","Principal component analysis","Feature extraction","Electronic mail","Data visualization","Security"
Publisher
ieee
Conference_Titel
Visualization for Cyber Security (VizSec), 2015 IEEE Symposium on
Type
conf
DOI
10.1109/VIZSEC.2015.7312772
Filename
7312772
Link To Document