Potential Malicious Insiders Detection Based on a Comprehensive Security Psychological Model

Guang Yang,Lijun Cai,Yuaimin,Jiangang Ma,Dan Meng,Yu Wu
DOI: https://doi.org/10.1109/bigdataservice.2018.00011
2018-01-01
Abstract:The insider threat continues to be a paramount cyber security challenge that threatens individuals, financial enterprises and governmental organizations. To deter insider threats, traditional detection, which mainly focuses on policy checks and anomaly detection for users' computers and network activities, has been studied widely. However, because insiders have intrinsic authorized access at attack under normal behavior profiles, it is necessary to integrate the attackers' psychological characteristics. This work proposes a novel detection approach for potential malicious insiders based on a comprehensive security psychological model derived from Big-5 and Dark Triad personality traits, overcoming the biased choice and equality hypothesis problems in previous work. Moreover, the threat confidence degree is proposed to identify pseudo abnormal users and to markedly reduce the false positive rate. The experimental results illustrate the effectiveness and feasibility of the proposed approach, which has a very low false negative rate, and lay the foundation for a promising insider threat detection approach that integrates the attackers' psychological traits with the attack-chain characteristics.
What problem does this paper attempt to address?