Skip to main navigation Skip to search Skip to main content

Detecting masquerading users in a document management system

  • SUNY Buffalo

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

10 Scopus citations

Abstract

A Document Management System (DMS) is a repository of digital documents that provides functionality for check-in, check-out and shared editing. In a DMS, security mechanisms like encryption of documents and enforcement of policies are implemented to protect from information leakage. These security schemes, essentially applications of Digital Rights Management technologies, while effective against external attacks, are ineffective against insider attacks. The typical insider in a DMS already has access to documents and hence, his capabilities for information leakage are much higher. In this work, we address an important, yet unexplored problem of masquerading users in a DMS, a threat for which the DMS inherently has no protection. We approach the problem by monitoring the pattern and mannerism of user actions on documents and building a profile of each user using the resulting logs. In order to illustrate our ideas, we built user profiles of 41 users working on Microsoft Word and applied two algorithms, viz., IPAM and Naïve Bayes to distinguish between them. When supplied with appropriately interpreted command sequences of a DMS, IPAM was able to distinguish between users effectively, while Naïve Bayes failed to produce any meaningful results. We recorded an average detection rate of 58% with a false positive of 14%.

Original languageEnglish
Title of host publication2006 IEEE International Conference on Communications, ICC 2006
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages2296-2301
Number of pages6
ISBN (Print)1424403553, 9781424403554
DOIs
StatePublished - 2006
Event2006 IEEE International Conference on Communications, ICC 2006 - Istanbul, Turkey
Duration: Jul 11 2006Jul 15 2006

Publication series

NameIEEE International Conference on Communications
Volume5
ISSN (Print)0536-1486

Conference

Conference2006 IEEE International Conference on Communications, ICC 2006
Country/TerritoryTurkey
CityIstanbul
Period07/11/0607/15/06

Keywords

  • Digital rights management
  • Document management system
  • Insider threat
  • Intrusion detection
  • Masquerading insiders
  • User profiling

Fingerprint

Dive into the research topics of 'Detecting masquerading users in a document management system'. Together they form a unique fingerprint.

Cite this