Title
Business Process Mining based Insider Threat Detection System.
Abstract
This paper introduces a Business Process Mining Based Insider Threat Detection System. The system firstly establishes the normal profiles of business activities and the operators by mining event logs, and then detects specific anomalies by comparing the content and the order of execution logs with the corresponding normal profile in order to find out the insiders and the threats they have brought. The anomalies concerned are defined and the corresponding detection algorithms are presented. We have performed experimentation using the ProM framework and Java programming with five synthetic business cases, and found that the system can effectively identify anomalies of both operators and business activities that may be indicative of potential insider threat.
Year
DOI
Venue
2016
10.1007/978-3-319-49109-7_44
ADVANCES ON P2P, PARALLEL, GRID, CLOUD AND INTERNET COMPUTING
Field
DocType
Volume
Business process mining,Business case,Computer security,Business activities,Insider threat,Operator (computer programming),Engineering,Java
Conference
1
ISSN
Citations 
PageRank 
2367-4512
0
0.34
References 
Authors
0
4
Name
Order
Citations
PageRank
Taiming Zhu100.68
Yuanbo Guo288983.95
Jun Ma34719.80
Ankang Ju400.34