Analysis and detection of insider attacks using behaviour rule based architecture in enterprise multitenancy
Santosh Kumar Hengehingesanthosh@gmail.comsantosh.henge@jaipur.manipal.eduDepartment of Directorate of Online EducationJaipur 302034, RajasthanManipal University JaipurIndiaView full profile → , Aditya Upadhyayadityaupadhyay144@gmail.comDepartment of Directorate of Online EducationJaipur 302034, RajasthanManipal University JaipurIndiaView full profile → , Ashok Kumar Sainishksaini@gmail.comDepartment of Computer Science & EngineeringJaipur 302034, RajasthanManipal University JaipurIndiaView full profile → , Neha Mishraneha.rbt@gmail.comDepartment of Computer Science & Engineering, JaipurJaipur 303905, RajasthanJECRC UniversityIndiaView full profile → , Dimpal Sharmadimpal286@gmail.comDepartment of Computer Science & Engineering, JaipurJaipur 303905, RajasthanJECRC UniversityIndiaView full profile → , *Gajanand SharmaCorresponding authorgajanan.sharma@gmail.comDepartment of Computer Science & Engineering, JaipurJaipur 303905, RajasthanJECRC UniversityIndiaView full profile →
* Corresponding author · click or hover a name for details
- Published Online:
- 01 Apr 2023
- Article type:
- Research Article
- Language:
- EN
- Article no.:
- JDMSC-1743
- Pages:
- 707–718
Abstract
Keywords
Subject Classifications
References
[1] Jeremy, Understanding the “Insider Threat” https://cloudtweaks.com/2015/01/4-different-types-attacks-understanding-insider-threat/.
[2] Understanding Insider Threat: A Framework for Characterising
Attacks, http://ieeexplore.ieee.org/document/6957307/?reload=true.
[3] Jason R.C. Nurse,, Oliver Buckley, Philip A. Legg, Michael Goldsmith, Sadie Creese, Gordon R.T. Wright, Monica Whitty, Understanding Insider Threat: A Framework for Characterising Attacks, 2014 IEEE Security and Privacy Workshops. http://www.ieee-security.org/TC/SPW2014/papers/5103a214.PDF.
[4] J. Lee, A. Alghamdi and A. K. Zaidi, “Creating a Digital Twin of an Insider Threat Detection Enterprise Using Model-Based Systems Engineering,” 2022 IEEE International Systems Conference (SysCon), 2022, pp. 1-7, doi: 10.1109/SysCon53536.2022.9773890.
[5] B. Bowen, M. Ben Salem, S. Hershkop, A. Keromytis and S. Stolfo, “Designing Host and Network Sensors to Mitigate the Insider
Threat,” in IEEE Security & Privacy, vol. 7, no. 6, pp. 22-29 (Nov.-Dec. 2009), doi: 10.1109/MSP.2009.109.
[6] P. Dhiman, S. K. Henge, S. Singh, A. Kaur, P. Singh et al., “Blockchain merkle-tree ethereum approach in enterprise multitenant cloud environment,” Computers, Materials & Continua, vol. 74, no.2, pp. 3297–3313 (2023).
[7] Dhiman, P.; Henge, S.K.; Ramalingam, R.; Dumka, A.; Singh, R.; Gehlot, A.; Rashid, M.; Alshamrani, S.S.; AlGhamdi, A.S.; Alshehri, A. Secure Token–Key Implications in an Enterprise Multi-Tenancy Environment Using BGV–EHC Hybrid Homomorphic Encryption. Electronics 2022, 11, 1942. https://doi.org/10.3390/electronics11131942.
[8] Alaa Alsaeed, Combating Insider Threats to Enterprise, https://www.academia.edu/37765548/Combating_Insider_Threats_to_Enterprise.
[9] Dou, Z., Khalil, I., Khreishah, A. and Al-Fuqaha, A., 2017. Robust insider attacks countermeasure for Hadoop: Design and implementation. IEEE Systems Journal.
[10] Li, W., Meng, W. and Horace, H.S., Enhancing collaborative intrusion detection networks against insider attacks using supervised intrusion sensitivity-based trust management model. Journal of Network and Computer Applications, 77, pp.135-145 (2017).
[11] Roy P. and Mazumdar C.. Modelling of Enterprise Insider Threats. DOI: 10.5220/0005327901320136 In Proceedings of the 1st International Conference on Information Systems Security and Privacy (ICISSP-2015), pages 132-136 ISBN: 978-989-758-081-9.
[12] Al-Mhiqani MN, Ahmad R, Zainal Abidin Z, Yassin W, Hassan A, Abdulkareem KH, Ali NS, Yunos Z. A Review of Insider Threat Detection: Classification, Machine Learning Techniques, Datasets, Open Challenges, and Recommendations. Applied Sciences. 2020; 10(15) : 5208. https://doi.org/10.3390/app10155208.
[13] Walker-Roberts, S.; Hammoudeh, M.; Dehghantanha, A. A Systematic Review of the Availability and Efficacy of Countermeasures to Internal Threats in Healthcare Critical Infrastructure. IEEE Access 2018, 6, 25167-25177.
[14] Nasr, P.M.; Yazdian-Varjani, A. Toward Operator Access Management in SCADA System: Deontological Threats Mitigation. IEEE Trans. Ind. Inform. 14, 3314-3324 (2017).
[15] Pitropakis, N.; Lambrinoudakis, C.; Geneiatakis, D. Till All Are One: Towards a Unified Cloud IDS. In Proceedings of the Trust, Privacy and Security in Digital Business; Fischer Hubner, S., Lambrinoudakis, C., Lopez, J., Eds.; Springer: New York, NY, USA, pp. 136-149 (2015).
[16] Al-Mhiqani, M.N.; Ahmad, R.; Yassin, W.; Hassan, A.; Abidin, Z.Z.; Ali, N.S.; Abdulkareem, K.H. Cyber-Security Incidents: A Review Cases in Cyber-Physical Systems. Int. J. Adv. Comput. Sci. Appl., 9, 499-508 (2018).
[17] Liu, L.; De Vel, O.; Han, Q.-L.; Zhang, J.; Xiang, Y. Detecting and Preventing Cyber Insider Threats: A Survey. IEEE Commun. Surv. Tutor., 20, 1397-1417 (2018).
[18] Ullah, F.; Edwards, M.; Ramdhany, R.; Chitchyan, R.; Babar, M.A.; Rashid, A. Data exfiltration: A review of external attack vectors and countermeasures. J. Netw. Comp. Appl., 101, 18-54 (2018).
[19] Ho, S.M.; Kaarst-Brown, M.; Benbasat, I. Trustworthiness Attribution: Inquiry Into Insider Threat Detection. J. Assoc. Inf. Sci. Technol., 69, 271-280 (2018).
[20] Rajamanickam, S. Vollala, S. Amin, R.; Ramasubramanian,N. Insider Attack Protection: Lightweight Password-Based Authentication Techniques Using ECC. IEEE Sys. J. PP, 1-12 (2019).
[21] Li, W.; Meng, W.; Kwok, L.F.; IP, H.H.S. Enhancing collaborative intrusion detection networks against insider attacks using supervised intrusion sensitivity-based trust management model. J. Netw. Comput. Appl., 77, 135-145 (2017).
[22] Callegati, F.; Giallorenzo, S.; Melis, A.; Prandini, M. Cloud-of-Things meets Mobility-as-a-Service: An insider threat perspective. Comput. Secur., 74, 277-295 (2018).
[23] Meryem, A.; Samira, D.; Bouabid, E.O.; Mouad, L. A novel approach in detecting intrusions using NSLKDD database and MapReduce programming. Procedia Comput. Sci., 110, 230-235 (2017).
[24] Lo, O.; Buchanan, W.J.; Griffiths, P.; Macfarlane, R. Distance Measurement Methods for Improved Insider Threat Detection. Secur. Commun. Netw. 2018, 5906368 (2018).
[25] Alizadeh, M.; Lu, X.; Fahland, D.; Zannone, N.; van der Aalst, W.M.P. Linking data and process perspectives for conformance analysis. Comput. Secur. 73, 172-193 (2018).
[26] Harilal, A.; Toffalini, F.; Homoliak, I.; Castellanos, J.H. Twos: A dataset of malicious insider threat behavior based on a gamified competition. J. Wirel. Mob. Netw. (2018) 1.
[27] P. Dhiman, S. K. Henge, “Comparative Analysis of Cloud Security Complexities and Past Proposed Non-Homomorphic and Homomorphic Encryption Methodologies with Limitation” in CRC Press, 4th International Conference on Information and Communication Technology for Competitive Strategies (ICTCS- 2019), pp: 787-799, December 13th-14th (2019).
[28] Dhiman, P., Henge, S.K. Analysis of Blockchain Secure Models and Approaches Based on Various Services in Multi-tenant Environment. In: Singh, P.K., Singh, Y., Chhabra, J.K., Illés, Z., Verma, C. (eds) Recent Innovations in Computing. Lecture Notes in Electrical Engineering, vol 855 (2022). Springer, Singapore. https://doi.org/10.1007/978-981-16-8892-8_42.
[29] ArnauErola, IoannisAgrafiotis, Michael Goldsmith, Sadie Creese, Insider-threat detection: Lessons from deploying the CITD tool in three multinational organisations, Journal of Information Security and Applications, Vol. 67, 2022, 103167, ISSN 2214-2126, https://doi.org/10.1016/j.jisa.2022.103167.
[30] Legg, P. A., Buckley, O., Goldsmith, M., & Creese, S. Automated insider threat detection system using user and role-based profile assessment. IEEE Systems Journal, 11(2), 503-512 (2017). https://doi.org/10.1109/JSYST.2015.2438442.




