Real Time Detection Framework of Insider Threat Based on Agent
CSTR:
Author:
Affiliation:

Clc Number:

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    In view of the internal threat behavior in enterprise information system, especially the abuse of internal user resource, we propose a real-time detection framework based on Agent, which can find malicious insider threat behavior by comparing identify permissions and abnormal operation behavior. The framework is composed of data acquisition module, detection module, audit module and response module. From 4 aspects of identity authentication, access control, operation audit and vulnerability detection, the function of the detection system is described, and the key technology is introduced in detail. The application example proves that the detection framework implements the functions of user's real name login, behavior detection and post audit, fundamentally prevent malicious insiders to obtain illegal data and provide response and intervention capabilities, improving the security of information system. In the end, we summarize the development trend of the internal threat detection technology.

    Reference
    Related
    Cited by
Get Citation

王振辉.基于Agent的内部威胁实时检测框架.计算机系统应用,2017,26(6):83-87

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:September 26,2016
  • Revised:November 21,2016
  • Adopted:
  • Online: June 08,2017
  • Published:
Article QR Code
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-3
Address:4# South Fourth Street, Zhongguancun,Haidian, Beijing,Postal Code:100190
Phone:010-62661041 Fax: Email:csa (a) iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063