International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1709862

1709862 Vol 6 · Issue 2 Download Paper

Beyond the Perimeter: Redefining Insider Threat Modeling through Adaptive Behavioral Analytics in Hybrid Work Environments

Tim Abdiukov

Subject area: Science,Engineering and Technology  ·  Area of research: Insider Threats

Abstract

The rise of the hybrid work model has highlighted the limitations of a perimeter-based approach to security and also reintroduced the concept of insider threats in a new and entirely different way. This research presents an overview of the historical development of the insider threat paradigm from the 1990s to the present year, 2021, and how conventional detection measures, which employ a combination of networks and static rules, no longer suffice in distributed work environments. The paper suggests the need to dynamically reconfigure the modeling of insider threats by introducing versatile, adaptive behavioral analytics ?an approach based on machine learning and ongoing user behavior profiling. The research paper is based on case studies, psychological theory, and technical advances in the field through 2021. It can be generalized as a hybrid-ready security model that combines behavioral cues, contextual awareness, and risk scoring to increase detection accuracy. This cross-functional exploration ultimately offers a broader approach to reducing insider threats in workplaces, which have become increasingly interesting and virtual in contemporary, more fluid work environments.

Keywords

Insider Threats; Adaptive Behavioral Analytics; Hybrid Work Environments; Behavioral Risk Scoring; Cybersecurity; UEBA

References

[1] Anderson, L., & Agarwal, R. (2010). Practicing safe computing: A multimedia empirical examination of home computer user security behavioral intentions. MIS Quarterly, 34(3), 613–643. https://doi.org/10.2307/25750694

[2] Bishop, M., & Gates, C. (2008). Defining the insider threat. Proceedings of the 4th Annual Workshop on Cyber Security and Information Intelligence Research, 1–3.

[3] Cappelli, D. M., Moore, A. P., & Trzeciak, R. F. (2012). The CERT guide to insider threats: How to prevent, detect, and respond to information technology crimes (Theft, sabotage, fraud). Addison-Wesley.

[4] Greitzer, F. L., & Frincke, D. A. (2010). Combining traditional cyber security audit data with psychosocial data: Towards predictive modeling for insider threat mitigation. Insider Threats in Cyber Security, 85–113. https://doi.org/10.1007/978-1-4419-7133-3_5

[5] Ponemon Institute. (2018). 2018 Cost of Insider Threats: Global Organizations. Retrieved from

[6] (2021). Insider threat. In Wikipedia, The Free Encyclopedia. Retrieved from https://en.wikipedia.org/wiki/Insider_threat

[7] Brdiczka, O., Liu, J., Price, B., Shen, J., Patil, A., Chow, R., Bart, E., & Ducheneaut, N. (2012). Proactive Insider Threat Detection through Graph Learning and Psychological Context. Proactive Insider Threat Detection Through Graph Learning and Psychological Context, 142–149. https://doi.org/10.1109/spw.2012.29

[8] George Silowash, Dawn Cappelli, Andrew Moore, Randall Trzeciak, Timothy J. Shimeall, Lori Flynn (December 2012)................ Common Sense Guide to Mitigating Insider Threats, 4th Edition. CERT

[9] Gheyas, I. A., & Abdallah, A. E. (2016). Detection and prediction of insider threats to cyber security: A systematic literature review and meta-analysis. Big Data Analytics, 1(6).

[10] Legg, P. A., Buckley, O., Goldsmith, M., & Creese, S. (2015). Automated insider threat detection system using user and role-based profile assessment. IEEE Systems Journal, 11(2), 503–512.

[11] Samek, W., Wiegand, T., & Müller, K. R. (2017). Explainable artificial intelligence: Understanding, visualizing, and interpreting deep learning models. arXiv preprint arXiv:1708.08296.

[12] Shokri, R., & Shmatikov, V. (2015). Privacy-preserving deep learning. Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, 1310–1321.

[13] Cappelli, D. M., Moore, A. P., & Trzeciak, R. F. (2012). The CERT guide to insider threats: How to prevent, detect, and respond to information technology crimes. Addison-Wesley.

[14] Eberle, W., & Holder, L. (2009). Insider threat detection using graph-based approaches. In Cybersecurity Applications & Technology Conference for Homeland Security, 2009 (pp. 237–241). IEEE.

[15] Magklaras, G., & Furnell, S. (2005). Insider Threat Prediction Tool: Evaluating the Probability of IT Misuse. Computers & Security, 21(1), 62–73.

[16] Salem, M. B., Hershkop, S., & Stolfo, S. J. (2008). A survey of insider attack detection research. In Insider Attack and Cyber Security (pp. 69–90). Springer.

[17] Axelsson, S. (2000). The base-rate fallacy and the difficulty of intrusion detection. ACM Transactions on Information and System Security (TISSEC), 3(3), 186–205.

[18] Denning, D. E. (1987). An intrusion-detection model. IEEE Transactions on Software Engineering, SE-13(2), 222–232.

[19] Eberle, W., & Holder, L. (2009). Insider threat detection using graph-based approaches. Journal of Applied Security Research, 4(1), 32–81.

[20] Laskov, P., Schäfer, C., Kotenko, I., Stepashkin, M., & Smirnov, A. (2005). Intrusion detection in unlabeled data with quarter-sphere support vector machines. Detection of Intrusions and Malware, and Vulnerability Assessment, 71–82.

[21] Magklaras, G., & Furnell, S. M. (2002). Insider Threat Prediction Tool: Evaluating the Probability of IT Misuse. Computers & Security, 21(1), 62–73.

[22] Sommer, R., & Paxson, V. (2010). Outside the closed world: On using machine learning for network intrusion detection. In 2010, IEEE Symposium on Security and Privacy (pp. 305–316). IEEE.

[23] Gheyas, I. A., & Abdallah, A. E. (2016). Detection and prediction of insider threats to cyber security: A systematic literature review and meta-analysis. Big Data Analytics, 1(6), 1–29.

[24] Greitzer, F. L., & Frincke, D. A. (2010). Combining traditional cyber security audit data with psychosocial data: Towards predictive modeling for insider threat mitigation. In Insider Threats in Cyber Security (pp. 85–113). Springer.

[25] Business Insider. (2021, April). Hybrid Work Will Change Everything, and Many Companies Are Not Ready. Retrieved from the Business Insider website.

[26] Nurse, J. R. C., Williams, N., Collins, E., Panteli, N., Blythe, J., & Koppelman, B. (2021). Remote Working Pre and PostCOVID19: An Analysis of New Threats and Risks to Security and Privacy. arXiv.

[27] Security Magazine. (2020, December 14). Combating insider threats in the age of remote work. Security Magazine.

[28] (2020). 2020 WorkforHome Shift: What We Learned. Threatpost.

[29] (2021, July 29). Tackling the insider threat to the new hybrid workplace. WeLiveSecurity.

[30] ADAMS Program. (2014). Anomaly Detection at Multiple Scales (ADAMS). DARPA.

[31] Mazzarolo, G., & Jurcut, A. D. (2019). A descriptive literature review and classification of insider threat research. arXiv preprint.

[32] Reardon, M. G.; Goldberg, Henry G.; Phillips, Brian J.(2011 - 2018) Proactive discovery of insider threats using graph analysis and learning PRODIGALProjecthttps://apps.dtic.mil/sti/citations/AD1058565 PRODIGAL Project. (2011). Proactive discovery of insider threats using graph analysis and learning. DARPA

[33] Rastogi, A., & Ma, Y. (2021). DANTE: Predicting insider threat using LSTM on system logs. arXiv.

[34] Yuan, S., & Wu, X. (2020). Deep Learning for Insider Threat Detection: A Review, Challenges, and Opportunities. arXiv.

[35] DARPA. (2011–2014). Anomaly Detection at Multiple Scales (ADAMS) project.

[36] Homoliak, Ivan & Toffalini, Flavio & Guarnizo, Juan & Elovici, Yuval & Ochoa, Martín. (2019). Insight Into Insiders and IT: A Survey of Insider Threat Taxonomies, Analysis, Modeling, and Countermeasures. ACM Computing Surveys. 52. 1-40. 10.1145/3303771.

[37] Brian Hymer (Nov 29, 2019) Mitigating the insider threat, step 1: Understand and control privilege.https://www.quest.com/community/blogs/b/performance-monitoring/posts/mitigating-the-insider-threat-step-1-understand-and-control-privilege

[38] Al-Mhiqani, M. N., Ahmad, R., Zainal Abidin, Z., Yassin, W., Hassan, A., Abdulkareem, K. H., Ali, N. S., & Yunos, Z. (2020). A Review of Insider Threat Detection: Classification, Machine Learning Techniques, Datasets, Open Challenges, and Recommendations. Applied Sciences, 10(15),5208.https://doi.org/10.3390/app10155208

[39] Astrid Wynne, Contributing Editor (Mar 31, 2015) Active risk assessment, global sharing at core of Nabors safety intervention program. https://drillingcontractor.org/activeriskassessment-global-sharing-at-core-of-nabors-safety-observation-card-33690

[40] Holistic CIS, Industry articles (September 18, 2019) The Hybrid model: a perfect mix of traditional and agile methodologies. https://www.openintl.com/hybridmodelaperfect-mix-of-traditional-and-agile-methodology/

How to cite this paper

Tim Abdiukov "Beyond the Perimeter: Redefining Insider Threat Modeling through Adaptive Behavioral Analytics in Hybrid Work Environments" Iconic Research And Engineering Journals Volume 6 Issue 2 2022 Page 393-404
Tim Abdiukov "Beyond the Perimeter: Redefining Insider Threat Modeling through Adaptive Behavioral Analytics in Hybrid Work Environments" Iconic Research And Engineering Journals, vol. 6, no. 2, Aug. 2022
Tim Abdiukov (2022). Beyond the Perimeter: Redefining Insider Threat Modeling through Adaptive Behavioral Analytics in Hybrid Work Environments. Iconic Research And Engineering Journals, 6(2).
Tim Abdiukov "Beyond the Perimeter: Redefining Insider Threat Modeling through Adaptive Behavioral Analytics in Hybrid Work Environments" Iconic Research And Engineering Journals, vol. 6, no. 2, Aug. 2022.
@article{1709862,
      author = {Tim Abdiukov},
      title = {Beyond the Perimeter: Redefining Insider Threat Modeling through Adaptive Behavioral Analytics in Hybrid Work Environments},
      journal = {Iconic Research And Engineering Journals},
      year = {2022},
      volume = {6},
      number = {2},
      pages = {393-404},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1709862.pdf},
      abstract = {The rise of the hybrid work model has highlighted the limitations of a perimeter-based approach to security and also reintroduced the concept of insider threats in a new and entirely different way. This research presents an overview of the historical development of the insider threat paradigm from the 1990s to the present year, 2021, and how conventional detection measures, which employ a combination of networks and static rules, no longer suffice in distributed work environments. The paper suggests the need to dynamically reconfigure the modeling of insider threats by introducing versatile, adaptive behavioral analytics ?an approach based on machine learning and ongoing user behavior profiling. The research paper is based on case studies, psychological theory, and technical advances in the field through 2021. It can be generalized as a hybrid-ready security model that combines behavioral cues, contextual awareness, and risk scoring to increase detection accuracy. This cross-functional exploration ultimately offers a broader approach to reducing insider threats in workplaces, which have become increasingly interesting and virtual in contemporary, more fluid work environments.},
      keywords = {Insider Threats; Adaptive Behavioral Analytics; Hybrid Work Environments; Behavioral Risk Scoring; Cybersecurity; UEBA},
      month = {August},
  }