Visible to the public A Tripwire Grammar for Insider Threat Detection

TitleA Tripwire Grammar for Insider Threat Detection
Publication TypeConference Paper
Year of Publication2016
AuthorsAgrafiotis, Ioannis, Erola, Arnau, Goldsmith, Michael, Creese, Sadie
Conference NameProceedings of the 8th ACM CCS International Workshop on Managing Insider Security Threats
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4571-2
Keywordsattack-pattern, Collaboration, Grammar, Human Behavior, human factors, insider threat, insider threats, Metrics, pubcrawl, Resiliency, security policies, tripwire
Abstract

The threat from insiders is an ever-growing concern for organisations, and in recent years the harm that insiders pose has been widely demonstrated. This paper describes our recent work into how we might support insider threat detection when actions are taken which can be immediately determined as of concern because they fall into one of two categories: they violate a policy which is specifically crafted to describe behaviours that are highly likely to be of concern if they are exhibited, or they exhibit behaviours which follow a pattern of a known insider threat attack. In particular, we view these concerning actions as something that we can design and implement tripwires within a system to detect. We then orchestrate these tripwires in conjunction with an anomaly detection system and present an approach to formalising tripwires of both categories. Our intention being that by having a single framework for describing them, alongside a library of existing tripwires in use, we can provide the community of practitioners and researchers with the basis to document and evolve this common understanding of tripwires.

URLhttp://doi.acm.org/10.1145/2995959.2995971
DOI10.1145/2995959.2995971
Citation Keyagrafiotis_tripwire_2016