Title :
Detecting Insider Threats: A Trust-Aware Framework
Author :
Paci, Federica ; Fernandez-Gago, Carmen ; Moyano, Francisco
Author_Institution :
Dept. of Inf. Eng. & Comput. Sci., Univ. of Trento, Trento, Italy
Abstract :
The number of insider threats hitting organizations and big enterprises is rapidly growing. Insider threats occur when trusted employees misuse their permissions on organizational assets. Since insider threats know the organization and its processes, very often they end up undetected. Therefore, there is a pressing need for organizations to adopt preventive mechanisms to defend against insider threats. In this paper, we propose a framework for insiders identification during the early requirement analysis of organizational settings and of its IT systems. The framework supports security engineers in the detection of insider threats and in the prioritization of them based on the risk they represent to the organization. To enable the automatic detection of insider threats, we extend the SI* requirement modeling language with an asset model and a trust model. The asset model allows associating security properties and sensitivity levels to assets. The trust model allows specifying the trust level that a user places in another user with respect to a given permission on an asset. The insider threats identification leverages the trust levels associated with the permissions assigned to users, as well as the sensitivity of the assets to which access is granted. We illustrate the approach based on a patient monitoring scenario.
Keywords :
business data processing; organisational aspects; personnel; specification languages; trusted computing; IT systems; SI* requirement modeling language; asset model; asset permission; asset sensitivity levels; big enterprises; insider threats detection; insider threats identification; insiders identification; organizational assets; organizations; preventive mechanisms; security engineers; security properties; trust model; trust-aware framework; trusted employees; Availability; Context; Drugs; Organizations; Security; Sensitivity; Silicon; insider threats; security requirements; trust relationships;
Conference_Titel :
Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
Conference_Location :
Regensburg
DOI :
10.1109/ARES.2013.22