Detecting insider threats in software systems using graph models of behavioral paths
Hemank Lamba, Thomas J. Glazier, Bradley R. Schmerl, Jürgen Pfeffer, David Garlan · 2015
Insider threats are a well-known problem, and previous studies have shown that it has a huge impact over a wide range of sectors like financial services, governments, critical infrastructure services and the telecommunications sector. Users, while interacting with any software system, leave a trace of what nodes they accessed and in what sequence. We propose to translate these sequences of observed activities into paths on the graph of the underlying software architectural model. We propose a clustering algorithm to find anomalies in the data, which can be combined with contextual information to confirm as an insider threat.