Title
Detecting insider threats in software systems using graph models of behavioral paths
Abstract
Insider threats are a well-known problem, and previous studies have shown that it has a huge impact over a wide range of sectors like financial services, governments, critical infrastructure services and the telecommunications sector. Users, while interacting with any software system, leave a trace of what nodes they accessed and in what sequence. We propose to translate these sequences of observed activities into paths on the graph of the underlying software architectural model. We propose a clustering algorithm to find anomalies in the data, which can be combined with contextual information to confirm as an insider threat.
Year
DOI
Venue
2015
10.1145/2746194.2746214
HotSoS
Keywords
Field
DocType
miscellaneous,path clustering,graph models,insider threats,complexity measures,software architecture,performance measures
Computer security,Computer science,Critical infrastructure,Software system,Insider threat,Software,Insider,Software architecture,Cluster analysis,Architectural model
Conference
Citations 
PageRank 
References 
0
0.34
1
Authors
5
Name
Order
Citations
PageRank
hemank lamba118316.59
Thomas J. Glazier231.40
Bradley Schmerl3130875.34
Jürgen Pfeffer434626.57
David Garlan57861761.63