A NEW TAXONOMY OF INSIDER THREATS; AN INITIAL STEP IN UNDERSTANDING AUTHORIZED ATTACK

Ameera Natasha Mohammad, Nathan Clarke, Aslinda Hassan, Warusia Mohamed Yassin, Zaheera Zainal Abidin, Mohammed Nasser Al‐Mhiqani, Rabiah Bt Ahmad · International Journal of Information Systems and Management · 2018

Insider threat represents one of the greatest challenges in the cyber security world. Insider attackers have more privileged and legitimate access to the information and facilities, compared to the outsider attackers. In fact, insider attacker has more accessibilities and higher potential to bring huge damage to the organisation. However, the behaviour of the insider attacker generates many questions to ponder before a new taxonomy is created. Therefore, the main objective of this paper is two-fold: a) to classify the insider threat for better understanding; b) propose a new taxonomy for insider threat with terminologies. To obtain the objective, the process starts with collecting and classifying the evident. Then, this study presents a hybrid insider threat classification based on combining insider threat access, motivation, indicator, types and actions, profile categorisation, methods, and detection techniques. With the insights afforded by looking more closely at conceptual understanding, we describe how classification of insider threat may effectively be used in insider threat detection.

Read the paper · More papers on PaperTik