Detecting Malicious Insiders in Military Networks

Abstract

Given that a network is only as strong as its weakest link, a key vulnerability to network centric warfare is the threat from within. This paper summarizes several recent MITRE efforts focused on characterizing and automatically detecting malicious insiders within modern information systems. Malicious insiders (MI) adversely impact an organization's mission through a range of actions that compromise information confidentiality, integrity, and/or availability. Their strong organizational knowledge, varying range of abusive behaviors, and ability to exploit legitimate access makes their detection particularly challenging. Crucial balances must be struck while performing MI detection. Detection accuracy must be weighed against minimizing time-to-detect and aggregating diverse audit data must be balanced against the need to protect the data from abuse. Key lessons learned from our MI research include the need to understand the context of the user's actions, the need to establish models of normal behavior, the need to reduce the time to detect malicious behavior, the value of non cyber-observables, and the importance of real-world data collections to evaluate potential solutions.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Jan 01, 2006
Accession Number
ADA456254

Entities

People

  • Mark Maybury

Organizations

  • MITRE Corporation

Tags

Communities of Interest

  • Cyber

DTIC Thesaurus Topics

  • Abstracts
  • Accuracy
  • Anomaly Detection
  • Change Detection
  • Data Fusion
  • Detection
  • Detectors
  • Electronic Mail
  • Human Behavior
  • Information Operations
  • Information Systems
  • Insider Threats
  • Intrusion Detection
  • Lessons Learned
  • Network Protocols
  • Security
  • Software Agents

Fields of Study

  • Computer science

Readers

  • Cybersecurity.
  • Military History / Militaries and War Studies
  • Team-Based Human-Centered Cognitive Task Decision Making and Information Performance.

Technology Areas

  • Cyber