Detecting collaborative insider attacks in information systems

Khanh Nguyen Viet, Brajendra Panda, Yi Hu · 2012

The overall goals of information security are to ensure the confidentiality, integrity, and availability of the data in the systems. In addition to the common outsider attacks, insider attacks are often inadequately checked by the security mechanisms. This paper addresses the problem of collaborative insider attacks where two or more insiders work together to compromise critical data in the information systems. It first discusses the relations among the system components and the illegal information flow diagram. Then, the characteristics of data accesses profiled by the mutual-access-record's probability value and distance of transaction to data item are presented. The algorithm for detecting collaborative insider attacks is introduced afterwards. Moreover, simulation experiments were conducted to verify the effectiveness of the proposed approach.

Read the paper · More papers on PaperTik