Guest editorial: A brief overview of data leakage and insider threats
Generate an AI Snapshot to get a quick, structured summary of this paper.
A concise AI-generated summary of the paper will appear here once you click Generate AI Snapshot.
Abstract
1 IntroductionThe challenges of preventing, detecting, and responding todata leakage propagated by authorized users, orinsiderthreats, are among the most difficult facing security re-searchers and professionals today. Prior to the advent ofcomputing,security expertsidentifiedpotential insiderthreatsby examining suspicious activities in a person’s physicalbehavior. While still relevant in the modern era, we mustnow also detect suspicious activity in a person’sbehavioroninformation systems. But the result is still fundamentally thesame: malicious insiders continue to succeed in harmingorganizations by leaking sensitive information.Research addressing this problem continues feverishly,but some critical questions remain unanswered. First, can aperson’s intent be accurately characterized by monitoringand analyzing interactions with computing systems? That is,are the observations made by monitoring and auditing sys-tems robust enough to allow automated characterization ofmalicious versus non-malicious behavior (or even informedguesses)? Secondly, is the malicious technical behavior ofinsiders anomalous any more often than the behavior ofnon-malicious users? If so, how often are malicious activi-ties clearly anomalous? Finally, is anomalous behavior in-dicative of potential malicious intent, ordomost insiders fallwithin the boundaries of normal behavior with respect tothemselves, their peers, and their organization?Researchers approach this problem from many differentangles. Some propose highly technical solutions, using tech-niques applied to “Big Data,” or various statistical or graphanalyticmethods.Othersattempttodiscerntheuser’sintentordisposition via semantic, linguistic, or sentiment analysis ofcommunication such as email or instant messaging. Stillothers propose combined approaches including analysis oftechnical events combined with observed behaviors not relat-edtocomputing systems.Whateverthe approach, researchersstillstruggletodefinetheproblem,muchlessdemonstratetheoperational validity of their solutions. In this journal, wedocument four new approaches seeking to address compo-nents of the problem, with the goal of reducing the harmmalicious insiders can inflict on an organization.2 Defining and characterizing insider threatsOne ofthe mostimportant elementsin any field ofresearchisthe common vernacular researchers use to describe problemsand solutions. Unfortunately, insider threat and data leakageresearch has yet to fully mature in this respect. The literaturepresentsavarietyofdefinitionsandcharacteristicsofinsiders.These characterizations often focus on different aspects ofinsider activity, which can be classified as technical, social,or socio-technical approaches to studying insider crime. Forexample, technical characteristics are the focus of Phyo andFurnell’s taxonomy of insider threats,which describes insideractivity in terms of network level, system level, andapplication-anddata-levelmisuses(2004).ThesocialaspectsarethefocusofWood’sattributesofaninsider,whichincludeaccess, knowledge, privileges, skills, risk, tactics, motivation,
