Skip to main navigation Skip to search Skip to main content

A preliminary cyber ontology for insider threats in the financial sector

  • SUNY Buffalo

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

8 Scopus citations

Abstract

Insider attack has become a major threat in financial sector and is a very serious and pervasive security problem. Currently, there is no insider threat ontology in this domain and such an ontology is critical to developing countermeasures against insider attacks. In this paper, we create an ontology focusing on insider attacks in the banking domain targeting database systems. We define the taxonomy used in this ontology and identify the relationships between the ontology classes. The resulting structure is a domain ontology mapped onto the Suggested Upper Merged Ontology (SUMO), Friend of a Friend(FOAF) and Finance ontologies to make our work integrable to the systems that use these ontologies and to create a broad knowledge base. The attack types we formulate in the ontology are masquerade, privilege elevation, privilege abuse and collusion attacks. Our model could be used to systematically evaluate any insider threat detection schemes in a realistic way and discover attacks that share similarities with previously identified attacks.

Original languageEnglish
Title of host publicationMIST 2015 - Proceedings of the 7th ACM CCS International Workshop on Managing Insider Security Threats, co-located with CCS 2015
PublisherAssociation for Computing Machinery, Inc
Pages75-78
Number of pages4
ISBN (Electronic)9781450338240
DOIs
StatePublished - Oct 16 2015
Event7th ACM CCS International Workshop on Managing Insider Security Threats, MIST 2015 - Denver, United States
Duration: Oct 12 2015 → …

Publication series

NameMIST 2015 - Proceedings of the 7th ACM CCS International Workshop on Managing Insider Security Threats, co-located with CCS 2015

Conference

Conference7th ACM CCS International Workshop on Managing Insider Security Threats, MIST 2015
Country/TerritoryUnited States
CityDenver
Period10/12/15 → …

Keywords

  • Cyber ontology
  • Financial sector
  • Relational database systems
  • Taxonomy

Fingerprint

Dive into the research topics of 'A preliminary cyber ontology for insider threats in the financial sector'. Together they form a unique fingerprint.

Cite this