Skip to main navigation Skip to search Skip to main content

Insider threat analysis using information-centric modeling

  • Duc Ha
  • , Shambhu Upadhyaya
  • , Hung Ngo
  • , Suranjan Pramanhik
  • , Ramkumar Chinchani
  • , Sunu Mathew
  • SUNY Buffalo
  • Cisco Systems

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

15 Scopus citations

Abstract

Capability acquisition graphs (CAGs) provide a powerful framework for modeling insider threats, network attacks and system vulnerabilities. However, CAG-based security modeling systems have yet to be deployed in practice. This paper demonstrates the feasibility of applying CAGs to insider threat analysis. In particular, it describes the design and operation of an information-centric, graphics-oriented tool called ICMAP. ICMAP enables an analyst without any theoretical background to apply CAGs to answer security questions about vulnerabilities and likely attack scenarios, as well as to monitor network nodes. This functionality makes the tool very useful for attack attribution and forensics.

Original languageEnglish
Title of host publicationAdvances in Digital Forensics III
Subtitle of host publicationIFIP International Conference on Digital Forensics, National Centre for Forensic Science, Orlando, Florida, January 28-January 31, 2007
EditorsPhilip Craiger, Sujeet Shenoi
Pages55-73
Number of pages19
DOIs
StatePublished - 2007

Publication series

NameIFIP International Federation for Information Processing
Volume242
ISSN (Print)1571-5736

Keywords

  • Capability acquisition graphs
  • Insider threats
  • Key challenge graphs

Fingerprint

Dive into the research topics of 'Insider threat analysis using information-centric modeling'. Together they form a unique fingerprint.

Cite this