Insider Threat Detection Technology of Information System
CSTR:
Author:
Affiliation:

Clc Number:

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    In view of the increasingly serious internal threat behaviors in enterprise information system, especially the behaviors such as pseudonym login and unauthorized operation, based on the technology of user behavior analysis, a layered security model with a mixture of subject and object is adopted to establish a new internal threat detection framework of information system. Malicious insider threat behavior is found by comparing the abnormal behavior of users and the authority of subject and object. Regular expression and mixed encryption algorithm are used to ensure the accuracy of detection and log security. Security detection is carried out from four aspects: identity authentication, access control, operation audit, and behavior threshold technology. The key technologies are introduced in detail. Experiments show that the proposed detection framework can prevent internal personnel from stealing data, provide response and intervention capabilities, and improve the security of information systems. Finally, the development trend of internal threat detection technology is prospected.

    Reference
    Related
    Cited by
Get Citation

王振辉,王振铎,姚全珠.信息系统内部威胁检测技术研究.计算机系统应用,2019,28(12):219-225

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:April 06,2019
  • Revised:May 08,2019
  • Adopted:
  • Online: December 13,2019
  • Published: December 15,2019
Article QR Code
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-3
Address:4# South Fourth Street, Zhongguancun,Haidian, Beijing,Postal Code:100190
Phone:010-62661041 Fax: Email:csa (a) iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063