• skip to content
  • skip to navigation
  • skip to supporting content
Homepage
CLOK - Central Lancashire Online Knowledge
Menu
  • Home
  • About
  • Policies
  • Deposit Guide: Research eTheses
  • Copyright Guide
  • Contact
  • Links
    • Login
  • Deposit
  • Search Item
  • Search FullText
  • Browse

Defense against Insider Threat: a Framework for Gathering Goal-based Requirements

Tools
- Tools
+ Tools

Franqueira, Virginia N.L. and van Eck, Pascal (2006) Defense against Insider Threat: a Framework for Gathering Goal-based Requirements. Project Report. Centre for Telematics and Information Technology, University of Twente, Enschede.

[img]
Preview
PDF - Published Version
497Kb

Abstract

Insider threat is becoming comparable to outsider threat in frequency of security events. This is a very worrying situation, as insider attacks have a high probability of success because insiders have authorized access and legitimate privileges. As a result, organizations can suffer financial losses and damage to assets and to reputation. Despite their importance, insider threats are still not properly addressed by organizations. We contribute to reverse this situation by introducing a framework composed of a method and of supporting awareness deliverables. The method organizes the identification and assessment of insider threat risks from the perspective of the organization goal(s)/business mission. This method is supported by three deliverables. First, by attack strategies structured in four decomposition trees. Second, by a pattern of insider attack which reduces an insider attack step to six possible scenarios. Third, by a list of defense strategies which helps on the elicitation of requirements. The output of the method consists of goal-based requirements for the defense against insiders. Attack and defense strategies are collected from the literature and from organizational control principles.


Item Type:Monograph (Project Report)
Uncontrolled Keywords (separate with ;):Insider threat; control principles; attack strategies; defense strategies; risk assessment
Subjects:Q Science > Q Science (General)
Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Schools:School of Computing Engineering & Physcial Sciences
ID Code:6093
Deposited By: Carmit Erez
Deposited On:01 Nov 2012 16:36
Last Modified:01 Nov 2012 16:36

Repository Staff Only: item control page

University of Central Lancashire

Preston,
Lancashire,
PR1 2HE

Tel: +44 (0)1772 201 201

Other Links

  • Contact UCLan
  • How to find us
  • Help

  • Facebook
  • Twitter
  • UCLan RSS
  • Contact UCLan
  • Copyright |
  • Disclaimer |
  • Data Protection Act |
  • Freedom of Information