TY - GEN
T1 - Complexity of insider attacks to databases
AU - Kul, Gokhan
AU - Upadhyaya, Shambhu
AU - Hughes, Andrew
N1 - Publisher Copyright:
© 2017 ACM.
PY - 2017/10/30
Y1 - 2017/10/30
N2 - Insider attacks are one of the most dangerous threats to an organization. Unfortunately, they are very difficult to foresee, detect, and defend against due to the trust and responsibilities placed on the employees. In this paper, we first define the notion of user intent, and construct a model for the most common threat scenario used in the literature that poses a very high risk for sensitive data stored in the organization's database. We show that the complexity of identifying pseudo-intents of a user is coNP-Complete in this domain, and launching a harvester insider attack within the boundaries of the defined threat model takes linear time while a targeted threat model is an NP-Complete problem. We also discuss about the general defense mechanisms against the modeled threats, and show that countering against the harvester insider attack model takes quadratic time while countering against the targeted insider attack model can take linear to quadratic time depending on the strategy chosen. Finally, we analyze the adversarial behavior, and show that launching an attack with minimum risk is also an NP-Complete problem.
AB - Insider attacks are one of the most dangerous threats to an organization. Unfortunately, they are very difficult to foresee, detect, and defend against due to the trust and responsibilities placed on the employees. In this paper, we first define the notion of user intent, and construct a model for the most common threat scenario used in the literature that poses a very high risk for sensitive data stored in the organization's database. We show that the complexity of identifying pseudo-intents of a user is coNP-Complete in this domain, and launching a harvester insider attack within the boundaries of the defined threat model takes linear time while a targeted threat model is an NP-Complete problem. We also discuss about the general defense mechanisms against the modeled threats, and show that countering against the harvester insider attack model takes quadratic time while countering against the targeted insider attack model can take linear to quadratic time depending on the strategy chosen. Finally, we analyze the adversarial behavior, and show that launching an attack with minimum risk is also an NP-Complete problem.
KW - Complexity analysis
KW - Insider threat
KW - Query intent
KW - Query logs
KW - Threat modeling
UR - https://www.scopus.com/pages/publications/85043374302
U2 - 10.1145/3139923.3139927
DO - 10.1145/3139923.3139927
M3 - Conference contribution
AN - SCOPUS:85043374302
T3 - MIST 2017 - Proceedings of the 2017 International Workshop on Managing Insider Security Threats, co-located with CCS 2017
SP - 25
EP - 32
BT - MIST 2017 - Proceedings of the 2017 International Workshop on Managing Insider Security Threats, co-located with CCS 2017
PB - Association for Computing Machinery, Inc
T2 - 9th ACM CCS International Workshop on Managing Insider Security Threats, MIST 2017
Y2 - 30 October 2017
ER -