Insider threat detection using situation-aware MAS
John Buford, L. Lewis, Gabriel Jakobson · International Conference on Information Fusion · 2008
Previous work in automating insider threat detection has included top-down analysis and fusion of events from network and system monitors. Situation-awareness can extend the capability of such techniques to include observables outside of cyber-space. The application of situation-management to insider threats is becoming more practical due to the growing volume of different types of transactions and social networking performed electronically as well as the increasing capability for surveillance. We describe our distributed architecture for insider threat detection based on our earlier work in situation-aware BDI agents. In addition we consider examples of using the agent-based approach to simulate insider behavior, both expected and malicious. This approach offers the potential of detecting changes in behavior patterns as well as mis-information activities.