The Experts below are selected from a list of 180 Experts worldwide ranked by ideXlab platform

Jua Montelibano - One of the best experts on this subject based on the ideXlab platform.

  • An Analysis of Technical Observations in Insider Theft of Intellectual Property Cases
    2018
    Co-Authors: Michael Hanley, Randall F. Trzeciak, Tyle Dea, Will Schroede, Ma Houy, Jua Montelibano
    Abstract:

    Since 2001, the Insider Threat team at the Software Engineering Institute's CERT program has built an extensive library and comprehensive database containing more than 550 cases of Insider crimes. More than 80 of those crimes involved theft of an organization's intellectual property by a Malicious Insider. These crimes can be particularly damaging to an organization because it is often difficult or impossible to recover from a loss of confidentiality. This report provides an overview of techniques employed by Malicious Insiders to steal intellectual property, including the types of assets targeted and the methods used to remove the information from a victim organization's control. The report closes with a brief discussion of mitigating factors and strategic items that an organization should consider when defending against Insider attacks on intellectual property.

  • Insider Threat Control: Using Centralized Logging to Detect Data Exfiltration Near Insider Termination
    2018
    Co-Authors: Michael Hanley, Jua Montelibano
    Abstract:

    Since 2001, the CERT Insider Threat Center has built an extensive library and comprehensive database containing more than 600 cases of crimes committed against organizations by Insiders. A significant class of Insider crimes, Insider theft of intellectual property, involves highly damaging attacks against organizations that result in significant tangible losses in the form of stolen business plans, customer lists, and other proprietary information. The Insider Threat Center's behavioral modeling of Insiders who steal intellectual property shows that many Insiders who stole their organization's intellectual property stole at least some of it within 30 days of their termination. This technical note presents an example of an Insider threat pattern based on this insight. It then presents an example implementation of this pattern on an enterprise-class system using the centralized log storage and indexing engine Splunk to detect Malicious Insider behavior on a network.

Michael Hanley - One of the best experts on this subject based on the ideXlab platform.

  • An Analysis of Technical Observations in Insider Theft of Intellectual Property Cases
    2018
    Co-Authors: Michael Hanley, Randall F. Trzeciak, Tyle Dea, Will Schroede, Ma Houy, Jua Montelibano
    Abstract:

    Since 2001, the Insider Threat team at the Software Engineering Institute's CERT program has built an extensive library and comprehensive database containing more than 550 cases of Insider crimes. More than 80 of those crimes involved theft of an organization's intellectual property by a Malicious Insider. These crimes can be particularly damaging to an organization because it is often difficult or impossible to recover from a loss of confidentiality. This report provides an overview of techniques employed by Malicious Insiders to steal intellectual property, including the types of assets targeted and the methods used to remove the information from a victim organization's control. The report closes with a brief discussion of mitigating factors and strategic items that an organization should consider when defending against Insider attacks on intellectual property.

  • Insider Threat Control: Using Centralized Logging to Detect Data Exfiltration Near Insider Termination
    2018
    Co-Authors: Michael Hanley, Jua Montelibano
    Abstract:

    Since 2001, the CERT Insider Threat Center has built an extensive library and comprehensive database containing more than 600 cases of crimes committed against organizations by Insiders. A significant class of Insider crimes, Insider theft of intellectual property, involves highly damaging attacks against organizations that result in significant tangible losses in the form of stolen business plans, customer lists, and other proprietary information. The Insider Threat Center's behavioral modeling of Insiders who steal intellectual property shows that many Insiders who stole their organization's intellectual property stole at least some of it within 30 days of their termination. This technical note presents an example of an Insider threat pattern based on this insight. It then presents an example implementation of this pattern on an enterprise-class system using the centralized log storage and indexing engine Splunk to detect Malicious Insider behavior on a network.

  • A Pattern for Increased Monitoring for Intellectual Property Theft by Departing Insiders
    2018
    Co-Authors: Andrew P Moore, Michael Hanley, David Mundie
    Abstract:

    A research project at the CERT® Program is identifying enterprise architectural patterns to protect against the Insider threat to organizations. This report presents an example of such a pattern—Increased Monitoring for Intellectual Property (IP) Theft by Departing Insiders—to help organizations plan, prepare, and implement a means to mitigate the risk of Insider theft of IP. Our case data shows that many Insiders who stole IP did so within 30 days of their termination. Based on this insight, this pattern helps reduce that risk through increased monitoring of departing Insiders during their last 30 days of employment. The increased monitoring suggested by the pattern is above and beyond what might be required for a baseline organizational detection of potentially Malicious Insider actions. Future work will include development of a library of enterprise architectural patterns for mitigating the Insider threat based on the data we have collected. Our goal is for organizational resilience to Insider threat to emerge from repeated application of patterns from the library.

Prof Besty Haris - One of the best experts on this subject based on the ideXlab platform.

  • Wolf Routing to Detect Vampire Attacks in Wireless Sensor Networks
    2016
    Co-Authors: Prof Besty Haris
    Abstract:

    Abstract: Ad-hoc low-power wireless networks are a high price research direction in sensing and pervasive computing. Prior security work in this area has focused primarily on denial of communication at the routing or medium access control levels. This paper proposes a scheme to detect resource depletion attacks, called Vampire Attacks at the routing protocol layer, which permanently disable networks by quickly draining nodes’ battery power. The scheme is based on the preying behaviour of wolves. These “Vampire ” attacks are not specific to any specific protocol, but rather rely on the properties of many popular classes of routing protocols. Most of the general protocols are susceptible to Vampire attacks, which are devastating, difficult to detect, and are easy to carry out using as few as one Malicious Insider sending only protocol compliant messages. In the worst case, a single Vampire can increas

Haida Diana - One of the best experts on this subject based on the ideXlab platform.

  • AnyThreat: An Opportunistic Knowledge Discovery Approach to Insider Threat Detection
    2018
    Co-Authors: Haida Diana, Gaber, Mohamed Medha, Kovalchuk Yevgeniya
    Abstract:

    Insider threat detection is getting an increased concern from academia, industry, and governments due to the growing number of Malicious Insider incidents. The existing approaches proposed for detecting Insider threats still have a common shortcoming, which is the high number of false alarms (false positives). The challenge in these approaches is that it is essential to detect all anomalous behaviours which belong to a particular threat. To address this shortcoming, we propose an opportunistic knowledge discovery system, namely AnyThreat, with the aim to detect any anomalous behaviour in all Malicious Insider threats. We design the AnyThreat system with four components. (1) A feature engineering component, which constructs community data sets from the activity logs of a group of users having the same role. (2) An oversampling component, where we propose a novel oversampling technique named Artificial Minority Oversampling and Trapper REmoval (AMOTRE). AMOTRE first removes the minority (anomalous) instances that have a high resemblance with normal (majority) instances to reduce the number of false alarms, then it synthetically oversamples the minority class by shielding the border of the majority class. (3) A class decomposition component, which is introduced to cluster the instances of the majority class into subclasses to weaken the effect of the majority class without information loss. (4) A classification component, which applies a classification method on the subclasses to achieve a better separation between the majority class(es) and the minority class(es). AnyThreat is evaluated on synthetic data sets generated by Carnegie Mellon University. It detects approximately 87.5% of Malicious Insider threats, and achieves the minimum of false positives=3.36%

  • Opportunistic machine learning methods for effective Insider threat detection
    2018
    Co-Authors: Haida Diana
    Abstract:

    The topic of Insider threat detection is getting an increased concern from academia, industry, and governments due to the growing number of Malicious Insider incidents. A Malicious Insider threat is devised of a set of anomalous behaviours attributed to an Insider who exploit their privileges with the intention to compromise the confidentiality, integrity, or availability of the system or data. The existing approaches for detecting Insider threats still have a common shortcoming, which is the high number of false alarms (false positives), which deceives the system administrator(s) about suspicious behaviour of many users. To address the shortcoming of false alarms, in this thesis, we formulate an opportunistic approach to detect Insider threats with the aim of any-behaviour-all-threat detection. As a preliminary step, we apply feature engineering on the data logs of users’ behaviour. This work is conducted on synthetic CMU-CERT data sets which implement a variety of Malicious Insider threat scenarios. The maturity of data in an organisation is defined into three cases based on the availability of labelled data. We address the different cases of data maturity by proposing, developing, and evaluating machine learning approaches that incorporate techniques to reduce false alarms. The first presents a class imbalance approach, namely CD-AMOTRE, which combines the concept of Class Decomposition (CD) and a novel Artificial Minority Oversampling and Trapper REmoval (AMOTRE) technique. The second builds an adaptive one-class ensemble-based anomaly detection framework which introduces a progressive update method with an outlier aware artificial oversampling procedure. The third proposes a real-time anomaly detection approach, namely Ensemble of Random subspace Anomaly detectors In Data Streams (E-RAIDS). The proposed approaches detect most/all of the Malicious Insider threats, and achieve the minimum FP over the data sets compared to the existing machine learning approaches

  • Adaptive One-Class Ensemble-based Anomaly Detection: An Application to Insider Threats
    2018
    Co-Authors: Haida Diana, Gaber, Mohamed Medha
    Abstract:

    The Malicious Insider threat is getting increased concern by organisations, due to the continuously growing number of Insider incidents. The absence of previously logged Insider threats shapes the Insider threat detection mechanism into a one-class anomaly detection approach. A common shortcoming in the existing data mining approaches to detect Insider threats is the high number of False Positives (FP) (i.e. normal behaviour predicted as anomalous). To address this shortcoming, in this paper, we propose an anomaly detection framework with two components: one-class modelling component, and progressive update component. To allow the detection of anomalous instances that have a high resemblance with normal instances, the one-class modelling component applies class decomposition on normal class data to create k clusters, then trains an ensemble of k base anomaly detection algorithms (One-class Support Vector Machine or Isolation Forest), having the data in each cluster used to construct one of the k base models. The progressive update component updates each of the k models with sequentially acquired FP chunks; segments of a predetermined capacity of FPs. It includes an oversampling method to generate artificial samples for FPs per chunk, then retrains each model and adapts the decision boundary, with the aim to reduce the number of future FPs. A variety of experiments is carried out, on synthetic data sets generated at Carnegie Mellon University, to test the effectiveness of the proposed framework and its components. The results show that the proposed framework reports the highest F1 measure and less number of FPs compared to the base algorithms, as well as it attains to detect all the Insider threats in the data sets

  • Data Stream Clustering for Real-Time Anomaly Detection: An Application to Insider Threats
    Springer, 2018
    Co-Authors: Haida Diana, Gaber, Mohamed Medha
    Abstract:

    Insider threat detection is an emergent concern for academia, industries, and governments due to the growing number of Insider incidents in recent years. The continuous streaming of unbounded data coming from various sources in an organisation, typically in a high velocity, leads to a typical Big Data computational problem. The Malicious Insider threat refers to anomalous behaviour(s) (outliers) that deviate from the normal baseline of a data stream. The absence of previously logged activities executed by users shapes the Insider threat detection mechanism into an unsupervised anomaly detection approach over a data stream. A common shortcoming in the existing data mining approaches to detect Insider threats is the high number of false alarms/positives (FPs). To handle the Big Data issue and to address the shortcoming, we propose a streaming anomaly detection approach, namely Ensemble of Random subspace Anomaly detectors In Data Streams (E-RAIDS), for Insider threat detection. E-RAIDS learns an ensemble of p established outlier detection techniques [Micro-cluster-based Continuous Outlier Detection (MCOD) or Anytime Outlier Detection (AnyOut)] which employ clustering over continuous data streams. Each model of the p models learns from a random feature subspace to detect local outliers, which might not be detected over the whole feature space. E-RAIDS introduces an aggregate component that combines the results from the p feature subspaces, in order to confirm whether to generate an alarm at each window iteration. The merit of E-RAIDS is that it defines a survival factor and a vote factor to address the shortcoming of high number of FPs. Experiments on E-RAIDS-MCOD and E-RAIDS-AnyOut are carried out, on synthetic data sets including Malicious Insider threat scenarios generated at Carnegie Mellon University, to test the effectiveness of voting feature subspaces, and the capability to detect (more than one)-behaviour-all-threat in real-time. The results show that E-RAIDS-MCOD reports the highest F1 measure and less number of false alarm = 0 compared to E-RAIDS-AnyOut, as well as it attains to detect approximately all the Insider threats in real-time

N. Patil - One of the best experts on this subject based on the ideXlab platform.

  • Efficient Prevention of Vampire Attack in Ad-hoc Wireless Sensor Network
    2016
    Co-Authors: I. Mulla, Prof Rahul, N. Patil
    Abstract:

    Abstract — Ad-hoc low-power wireless networks are the challenging analysis direction in sensing and pervasive computing. Wireless Senor Network (WSN) basically use for security and energy efficiency. Early work on security in this area has been focused on denial of service (DOS) at the routing or medium access control (MAC) levels. Previously, the resource depletion attacks are considered as a routing problem, under this model are classified in to a new group called ―Vampire attacks‖. This difficult work examine thoroughly the identification of resource depletion attacks at the routing protocol layer and in the application layer, which completely disable networks by quickly exhausting nodes ’ battery power. Vampire attacks are not a protocol specific and they do not rely on design properties but rather exploits properties of protocol classes of routing protocols. Vampire attacks are liable to be influenced or harmed by a particular thing, which are disastrous, hard to find, and are easy to carry out using as few as one Malicious Insider sending only protocol compliant messages. A single Vampire can increase network-wide energy usage by a factor of O (N), where N in the number of network nodes, happens in worst case. In this work a detection and control strategy is proposed for these vampire attacks, along with a secure packet forwarding mechanism, which will keep safe from harm and danger Ad-hoc wireless nodes from power exhaust due to Vampires at packets forwarding level