login

Insiders and Insider Threats: An Overview of Definitions and Mitigation Techniques

Published 1 January 2011
Jeffrey Hunker, Christian W. Probst
Citations187

Abstract

Threats from the inside of an organization’s perimeters are a significant problem, since it is diffi-cult to distinguish them from benign activity. In this overview article we discuss defining properties of insiders and insider threats. After presenting definitions of these terms, we go on to discuss a num-ber of approaches from the technological, the sociological, and the socio-technical domain. We draw two main conclusions. Tackling insider threats requires a combination of techniques from the tech-nical, the sociological, and the socio-technical domain, to enable qualified detection of threats, and their mitigation. Another important observation is that the distinction between insiders and outsiders seems to loose significance as IT infrastructure is used in performing insider attacks. Little real-world data is available about the insider threat [1], yet recognizing when insiders are attempting to do something they should not on a corporate or organizational (computer) system is an important problem in cyber and organizational security in general. This “insider threat ” has received considerable attention, and is cited as one of the most serious security problems [2]1. It is also considered the most difficult problem to deal with because insiders often have information and capabilities not known to external attackers, and as a consequence can cause serious harm. Yet, little real-world data is

Keywords

Computer Science