Automated Scripting for Real-Time Responses to Suspicious User Actions

Foster Addo Yeboah, Mahanthi Ashok, Bukka Samudram Keerthi, Dorai Likitha Rani, Gaddam Shanmuka Ajay Kumar, Kandra Harshitha, Kandukuri Sukeerthi, Lnu Soujanya, Paruchuri Sri Sai Varun, Pillalamarri Tripura Sri Vaishnavi, Jones Yeboah, Owusu Nyarko‐Boateng · 2024

Automated scripting is very handy in scenarios as a response to suspicious user activities which helps companies in preventing cyber-attacks. This paper aims to understand the efficiency of automated scripts in detecting and preventing cyber threats, especially when done by insiders. The research will start by studying and reviewing the literature already existing on automated scripting and insider threats. It acts as a foundation to develop a framework that can be used in identifying and preventing such suspicious activities in realtime. Further, we will implement the scripting framework in a controlled simulation to understand its efficiency. The framework will be put into use for a few scenarios, that include unauthorized access to confidential data, and trials to extract that data. Firstly, the team created a script to automate and report unauthorized access of users to the System Administrator, secondly, created a script to automate and monitor system resources utilization by external processes and lastly created a script to automate and monitor external media connection to the system. In all these cases the System Administrator received an alert in his email address reporting suspicious user actions. The team came out with a framework showing the implementation of automated scripting in reporting suspicious user actions to System Administrators. The System Administrator, upon receiving these alerts, is well-informed about how to enhance the organization's cybersecurity posture by placing some restrictions on user activities if necessary. The findings from this research showed that organizations can leverage scripting languages in several ways to monitor suspicious activities.

Read the paper · More papers on PaperTik