An Intent-Driven Masquerader Detection Framework Based on Data Fusion

Xiaojun Chen,Jinqiao Shi,Yiguo Pu,Haoliang Zhang
DOI: https://doi.org/10.1007/978-3-642-35795-4_57
2013-01-01
Abstract:Different from outside attacks, malicious insiders steal sensitive data or sabotage information systems through misuse of privilege or identity theft (masquerader). These attacks, which are very hard to detect, can cause considerable damages to the organization. Most previous detection methods are based on single observable, which can find insider attacks to some extent; as for intent analysis, their usage seems to be limited. In this paper, we monitor users' various observables on host, and then build a new framework based on data fusion technique to locate this situation. Our framework is more precise for masquerader detection and capable of analyzing attack intents. © Springer-Verlag Berlin Heidelberg 2013.
What problem does this paper attempt to address?