The Experts below are selected from a list of 4683 Experts worldwide ranked by ideXlab platform
Huiyu Zhou - One of the best experts on this subject based on the ideXlab platform.
-
Insider Threat Risk Prediction based on Bayesian Network
2020Co-Authors: N Elmrabi, L Yang, S. H. Yang, Huiyu ZhouAbstract:Insider Threat protection has received increasing attention in the last ten years due to the serious con-sequences of malicious Insider Threats. Moreover, data leaks and the sale of mass data have become much simpler to achieve, e.g., the dark web can allow malicious Insiders to divulge confidential data whilst hiding their identities. In this paper, we propose a novel approach to predict the risk of malicious Insider Threats prior to a breach taking place. Firstly, we propose a new framework for Insider Threat risk prediction, drawing on technical, organisational and human factor perspectives. Secondly, we employ a Bayesian network to model and implement the proposed framework. Furthermore, this Bayesian network-based prediction model is evaluated in a range of challenging environments. The risk level predictions for each authorised users within the organisation are examined so that any in-sider Threat risk can be identified. The proposed Insider Threat prediction model achieved better results when compared to the empirical judgements of security experts.
-
Insider Threat Risk Prediction based on Bayesian Network
Computers & Security, 2020Co-Authors: Nebrase Elmrabit, S. H. Yang, L Yang, Huiyu ZhouAbstract:Abstract Insider Threat protection has received increasing attention in the last ten years due to the serious consequences of malicious Insider Threats. Moreover, data leaks and the sale of mass data have become much simpler to achieve, e.g., the dark web can allow malicious Insiders to divulge confidential data whilst hiding their identities. In this paper, we propose a novel approach to predict the risk of malicious Insider Threats prior to a breach taking place. Firstly, we propose a new framework for Insider Threat risk prediction, drawing on technical, organisational and human factor perspectives. Secondly, we employ a Bayesian network to model and implement the proposed framework. Furthermore, this Bayesian network-based prediction model is evaluated in a range of challenging environments. The risk level predictions for each authorised users within the organisation are examined so that any Insider Threat risk can be identified. The proposed Insider Threat prediction model achieved better results when compared to the empirical judgments of security experts
S. Upadhyaya - One of the best experts on this subject based on the ideXlab platform.
-
DSN - Towards a theory of Insider Threat assessment
2005 International Conference on Dependable Systems and Networks (DSN'05), 2005Co-Authors: Ramkumar Chinchani, A Iyer, S. UpadhyayaAbstract:Insider attacks are a well-known problem acknowledged as a Threat as early as 1980s. The Threat is attributed to legitimate users who abuse their privileges, and given their familiarity and proximity to the computational environment, can easily cause significant damage or losses. Due to the lack of tools and techniques, security analysts do not correctly perceive the Threat, and hence consider the attacks as unpreventable. In this paper, we present a theory of Insider Threat assessment. First, we describe a modeling methodology which captures several aspects of Insider Threat, and subsequently, show Threat assessment methodologies to reveal possible attack strategies of an Insider.
-
Towards a theory of Insider Threat assessment
2005 International Conference on Dependable Systems and Networks (DSN'05), 2005Co-Authors: Ramkumar Chinchani, A Iyer, S. UpadhyayaAbstract:Insider attacks are a well-known problem acknowledged as a Threat as early as 1980s. The Threat is attributed to legitimate users who abuse their privileges, and given their familiarity and proximity to the computational environment, can easily cause significant damage or losses. Due to the lack of tools and techniques, security analysts do not correctly perceive the Threat, and hence consider the attacks as unpreventable. In this paper, we present a theory of Insider Threat assessment. First, we describe a modeling methodology which captures several aspects of Insider Threat, and subsequently, show Threat assessment methodologies to reveal possible attack strategies of an Insider.
Nicole Lang Beebe - One of the best experts on this subject based on the ideXlab platform.
-
the dark side of the Insider detecting the Insider Threat through examination of dark triad personality traits
Hawaii International Conference on System Sciences, 2015Co-Authors: Michele Maasberg, John E Warren, Nicole Lang BeebeAbstract:Efforts to understand what goes on in the mind of an Insider have taken a back seat to developing technical controls, yet Insider Threat incidents persist. We examine Insider Threat incidents with malicious intent and propose an explanation through a relationship between Dark Triad personality traits and the Insider Threat. Although Dark Triad personality traits have emerged in Insider Threat cases and deviant workplace behavior studies, they have not been labeled as such and little empirical research has examined this phenomenon. This paper builds on previous research on Insider Threat and introduces ten propositions concerning the relationship between Dark Triad personality traits and Insider Threat behavior. We include behavioral antecedents based on the Theory of Planned Behavior and Capability Means Opportunity (CMO) model and the factors affecting those antecedents. This research addresses the behavioral aspect of the Insider Threat and provides new information in support of academics and practitioners.
-
HICSS - The Dark Side of the Insider: Detecting the Insider Threat through Examination of Dark Triad Personality Traits
2015 48th Hawaii International Conference on System Sciences, 2015Co-Authors: Michele Maasberg, John E Warren, Nicole Lang BeebeAbstract:Efforts to understand what goes on in the mind of an Insider have taken a back seat to developing technical controls, yet Insider Threat incidents persist. We examine Insider Threat incidents with malicious intent and propose an explanation through a relationship between Dark Triad personality traits and the Insider Threat. Although Dark Triad personality traits have emerged in Insider Threat cases and deviant workplace behavior studies, they have not been labeled as such and little empirical research has examined this phenomenon. This paper builds on previous research on Insider Threat and introduces ten propositions concerning the relationship between Dark Triad personality traits and Insider Threat behavior. We include behavioral antecedents based on the Theory of Planned Behavior and Capability Means Opportunity (CMO) model and the factors affecting those antecedents. This research addresses the behavioral aspect of the Insider Threat and provides new information in support of academics and practitioners.
Nebrase Elmrabit - One of the best experts on this subject based on the ideXlab platform.
-
Insider Threat Risk Prediction based on Bayesian Network
Computers & Security, 2020Co-Authors: Nebrase Elmrabit, S. H. Yang, L Yang, Huiyu ZhouAbstract:Abstract Insider Threat protection has received increasing attention in the last ten years due to the serious consequences of malicious Insider Threats. Moreover, data leaks and the sale of mass data have become much simpler to achieve, e.g., the dark web can allow malicious Insiders to divulge confidential data whilst hiding their identities. In this paper, we propose a novel approach to predict the risk of malicious Insider Threats prior to a breach taking place. Firstly, we propose a new framework for Insider Threat risk prediction, drawing on technical, organisational and human factor perspectives. Secondly, we employ a Bayesian network to model and implement the proposed framework. Furthermore, this Bayesian network-based prediction model is evaluated in a range of challenging environments. The risk level predictions for each authorised users within the organisation are examined so that any Insider Threat risk can be identified. The proposed Insider Threat prediction model achieved better results when compared to the empirical judgments of security experts
Binxing Fang - One of the best experts on this subject based on the ideXlab platform.
-
ICCS (1) - Insider Threat Detection with Deep Neural Network
Lecture Notes in Computer Science, 2018Co-Authors: Yuan Fangfang, Yanan Cao, Yanmin Shang, Yanbing Liu, Jianlong Tan, Binxing FangAbstract:Insider Threat detection has attracted a considerable attention from the researchers and industries. Existing work mainly focused on applying machine-learning techniques to detecting Insider Threat. However, this work requires “feature engineering” which is difficult and time-consuming. As we know, the deep learning technique can automatically learn powerful features. In this paper, we present a novel Insider Threat detection method with Deep Neural Network (DNN) based on user behavior. Specifically, we use the LSTM-CNN framework to find user’s anomalous behavior. First, similar to natural language modeling, we use the Long Short Term Memory (LSTM) to learn the language of user behavior through user actions and extract abstracted temporal features. Second, the extracted features are converted to the fixed-size feature matrices and the Convolutional Neural Network (CNN) use these fixed-size feature matrices to detect Insider Threat. We conduct experiments on a public dataset of Insider Threats. Experimental results show that our method can successfully detect Insider Threat and we obtained AUC = 0.9449 in best case.
-
Insider Threat detection with deep neural network
International Conference on Computational Science, 2018Co-Authors: Fangfang Yuan, Yanan Cao, Yanmin Shang, Yanbing Liu, Jianlong Tan, Binxing FangAbstract:Insider Threat detection has attracted a considerable attention from the researchers and industries. Existing work mainly focused on applying machine-learning techniques to detecting Insider Threat. However, this work requires “feature engineering” which is difficult and time-consuming. As we know, the deep learning technique can automatically learn powerful features. In this paper, we present a novel Insider Threat detection method with Deep Neural Network (DNN) based on user behavior. Specifically, we use the LSTM-CNN framework to find user’s anomalous behavior. First, similar to natural language modeling, we use the Long Short Term Memory (LSTM) to learn the language of user behavior through user actions and extract abstracted temporal features. Second, the extracted features are converted to the fixed-size feature matrices and the Convolutional Neural Network (CNN) use these fixed-size feature matrices to detect Insider Threat. We conduct experiments on a public dataset of Insider Threats. Experimental results show that our method can successfully detect Insider Threat and we obtained AUC = 0.9449 in best case.