Malicious Insider Threat Detection:A Conceptual Model
Tesleem Fagade, Theo Tryfonas · Bristol Research (University of Bristol) · 2017
The advent of Internet technologies, growing number of sophisticated hacking tools and mobile workforce creates a new dimension to the malicious insider problem for many organisations. In spite of the significant interest from researchers and industry experts, trusted employees with elevated access continue to pose insider challenges to organisation risk mitigation efforts. It is suggested that malicious insiders show certain personality traits, leave behind digital footprints and observable cyber risk behaviour in advance of an attack. This work offers a different perspective to address the insider problem by drawing concepts from behavioural theory, personality profiling and digital trails auditing. Instead of isolated treatments, our approach considers the intersection of different risk domains and aggregates risk scores from each as a predictor of malicious insider activities. This model has significant implication for security professionals, to draw insight from inextricably linked risk domains within the context of cybersecurity management. However, substantial empirical work is still needed to evaluate the model in real world cases.