Insider threat discovery using automatic detection of mission critical data based on content

Jonathan White, Brajendra Panda · 2010

In this work, we design a system that can automatically detect what is critical in data systems based upon the content and context of the information. After this process has been performed, the information it provides can be used for insider threat detection. If a DBMS is used for data access, historical logs are generally kept and our method uses these logs to detect the typical level of criticality of data that each user uses during normal work conditions. If a user suddenly attempts to access data that is much more critical than was typically accessed in the past, this is a potential sign that the insider is acting maliciously. Few attempts at locating critical data exist in the computer security literature and we argue in this work that our novel design fulfills this need in a manner that is extensible and applicable to a wide range of problems. Our results show that our design requires limited computing resources, and with proper training can be very effective at locating critical data and aiding in mitigating insider threats.

Read the paper · More papers on PaperTik