Insider Threats Meet Access Control: Insider Threats Detected Using Intent-based Access Control (IBAC) by Abdulaziz Almehmadi

Insider Threats Meet Access Control: Insider Threats Detected Using Intent-based Access Control (IBAC) by Abdulaziz Almehmadi

Author:Abdulaziz Almehmadi [Almehmadi, Abdulaziz]
Language: eng
Format: azw3
Published: 2019-01-09T16:00:00+00:00


Figure ‎4‑8. Experiment 2 tested Intent Categories.

Criteria for Selection of Images:

The criteria for image selection followed the method of Experiment 1 of selection by surveying 10 students to comment on what each potential image represents.

Procedure Discussion:

Participants were placed in a scenario in which they could be granted legitimate access to a computer. This setup simulates a real-life scenario of an employee gaining access to a data repository. By asking the participants not to open the Personal folder, we simulated a forbidden activity, even though they were able to perform this action. This serves as the abuse of privilege we encounter in insider threats. By stating which files exist in the Personal folder, we provided participants with details of what they could do and to what files. This also simulates a real insider threat scenario, as insiders are aware of the valuable information in an organization. Finally, we informed participants that if they open one of the private files and get caught, we will stop the experiment and they will fail to commit the maleficence without getting caught. We simulate specific acts that an employee is informed not to perform while signing their employment contract and what consequences they may encounter if they are guilty of such a breach.

Since each participant opened a certain file and in order to know what file a participant has opened, if they opened any, we used HyperCam [[xciv]], which records the participant’s actions while using the laptop. The main reason for asking participants not to report the file they plan to open or have opened is to address the psychological aspect of committing a wrongful act; they need to hide this action, which simulates a real-world scenario. We use the monitor recorder to investigate whether an abuse of privileges occurred or not and to assess the IBAC system to determine if it would have been able to prevent the insider threat. The recordings provide us information that we can use to verify the accuracy of the IBAC system.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.