Yet Another Intrusion Detection System against Insider Attacks

Hyeran MunKyusuk, Han Chan, Yeob Yeun, Kwangjo Kim · 2008

Intrusion Detection System (IDS) originated as a mechanism for managing the detection of system misuse through the analysis of activity (5). Despite that the various attacks are occurred by insiders and outsiders, most studied focused on IDS against outsider attacks. However, the loss from insider attacks is more severe than outsider attacks as shown in (10). In this paper, we improve the Wang et al.'s insider predection model (17) and propose the combined model with access control for the ecient insider intrusion detection. We delegate the role of intrusion detection to users, in order to detect the malicious insiders more eciently. If the insiders want to access to the information, they should have the permission from several users in organization. By combining the concept of access control in Wang et al.'s model, our scheme is believed to be more secure.

Read the paper · More papers on PaperTik