Analysis and detection of insider attacks using behaviour rule based architecture in enterprise multitenancy
Santosh Kumar Hengehingesanthosh@gmail.comDepartment of Directorate of Online Education Manipal University Jaipur Jaipur 302034 Rajasthan IndiaDepartment of Computer Science and Engineering School of Computer Science and Artificial Intelligence SR University Warangal, Telangana, 506371, IndiaView full profile → , Aditya Upadhyayadityaupadhyay144@gmail.comDepartment of Directorate of Online Education Manipal University Jaipur Jaipur 302034 Rajasthan IndiaDepartment of Computer Application Centre for Distance and Online Education Manipal University Jaipur Jaipur, Rajasthan, IndiaView full profile → , Ashok Kumar Sainiashok.saini@jaipur.manipal.eduDepartment of Computer Science & Engineering Manipal University Jaipur Jaipur 302034 Rajasthan IndiaDepartment of Computer Science and Engineering Manipal University JaipurJaipur, Rajasthan, 303007, IndiaView full profile → , Neha Mishraneha.rbt@gmail.comDepartment of Computer Science & Engineering, Jaipur JECRC University Jaipur 303905 Rajasthan IndiaView full profile → , Dimpal Sharmadimpal286@gmail.comDepartment of Computer Science & Engineering, Jaipur JECRC University Jaipur 303905 Rajasthan IndiaDepartment of Computer Science & Engineering JECRC University Jaipur Rajasthan IndiaView full profile → , *Gajanand SharmaCorresponding authorgajanan.sharma@gmail.comDepartment of Computer Science & Engineering, Jaipur JECRC University Jaipur 303905 Rajasthan IndiaDepartment of Computer Science & Engineering JECRC UniversityJaipur, Rajasthan, 303905, IndiaView full profile →
* Corresponding author · click or hover a name for details
- Published Online:
- 01 Apr 2023
- Article type:
- Research Article
- Language:
- EN
- Article no.:
- JDMSC-1743
- Pages:
- 707–718
Abstract
Keywords
Subject Classifications
References
[1] Jeremy, Understanding the “Insider Threat” https://cloudtweaks.com/2015/01/4-different-types-attacks-understanding-insider-threat/.
[2] Understanding Insider Threat: A Framework for Characterising
Attacks, http://ieeexplore.ieee.org/document/6957307/?reload=true.
[3] Jason R.C. Nurse,, Oliver Buckley, Philip A. Legg, Michael Goldsmith, Sadie Creese, Gordon R.T. Wright, Monica Whitty, Understanding Insider Threat: A Framework for Characterising Attacks, 2014 IEEE Security and Privacy Workshops. http://www.ieee-security.org/TC/SPW2014/papers/5103a214.PDF.
[4] J. Lee, A. Alghamdi and A. K. Zaidi, “Creating a Digital Twin of an Insider Threat Detection Enterprise Using Model-Based Systems Engineering,” 2022 IEEE International Systems Conference (SysCon), 2022, pp. 1-7, doi: 10.1109/SysCon53536.2022.9773890.
[5] B. Bowen, M. Ben Salem, S. Hershkop, A. Keromytis and S. Stolfo, “Designing Host and Network Sensors to Mitigate the Insider
Threat,” in IEEE Security & Privacy, vol. 7, no. 6, pp. 22-29 (Nov.-Dec. 2009), doi: 10.1109/MSP.2009.109.
[6] P. Dhiman, S. K. Henge, S. Singh, A. Kaur, P. Singh et al., “Blockchain merkle-tree ethereum approach in enterprise multitenant cloud environment,” Computers, Materials & Continua, vol. 74, no.2, pp. 3297–3313 (2023).
[7] Dhiman, P.; Henge, S.K.; Ramalingam, R.; Dumka, A.; Singh, R.; Gehlot, A.; Rashid, M.; Alshamrani, S.S.; AlGhamdi, A.S.; Alshehri, A. Secure Token–Key Implications in an Enterprise Multi-Tenancy Environment Using BGV–EHC Hybrid Homomorphic Encryption. Electronics 2022, 11, 1942. https://doi.org/10.3390/electronics11131942.
[8] Alaa Alsaeed, Combating Insider Threats to Enterprise, https://www.academia.edu/37765548/Combating_Insider_Threats_to_Enterprise.
[9] Dou, Z., Khalil, I., Khreishah, A. and Al-Fuqaha, A., 2017. Robust insider attacks countermeasure for Hadoop: Design and implementation. IEEE Systems Journal.
[10] Li, W., Meng, W. and Horace, H.S., Enhancing collaborative intrusion detection networks against insider attacks using supervised intrusion sensitivity-based trust management model. Journal of Network and Computer Applications, 77, pp.135-145 (2017).
[11] Roy P. and Mazumdar C.. Modelling of Enterprise Insider Threats. DOI: 10.5220/0005327901320136 In Proceedings of the 1st International Conference on Information Systems Security and Privacy (ICISSP-2015), pages 132-136 ISBN: 978-989-758-081-9.
[12] Al-Mhiqani MN, Ahmad R, Zainal Abidin Z, Yassin W, Hassan A, Abdulkareem KH, Ali NS, Yunos Z. A Review of Insider Threat Detection: Classification, Machine Learning Techniques, Datasets, Open Challenges, and Recommendations. Applied Sciences. 2020; 10(15) : 5208. https://doi.org/10.3390/app10155208.
[13] Walker-Roberts, S.; Hammoudeh, M.; Dehghantanha, A. A Systematic Review of the Availability and Efficacy of Countermeasures to Internal Threats in Healthcare Critical Infrastructure. IEEE Access 2018, 6, 25167-25177.
[14] Nasr, P.M.; Yazdian-Varjani, A. Toward Operator Access Management in SCADA System: Deontological Threats Mitigation. IEEE Trans. Ind. Inform. 14, 3314-3324 (2017).
[15] Pitropakis, N.; Lambrinoudakis, C.; Geneiatakis, D. Till All Are One: Towards a Unified Cloud IDS. In Proceedings of the Trust, Privacy and Security in Digital Business; Fischer Hubner, S., Lambrinoudakis, C., Lopez, J., Eds.; Springer: New York, NY, USA, pp. 136-149 (2015).
[16] Al-Mhiqani, M.N.; Ahmad, R.; Yassin, W.; Hassan, A.; Abidin, Z.Z.; Ali, N.S.; Abdulkareem, K.H. Cyber-Security Incidents: A Review Cases in Cyber-Physical Systems. Int. J. Adv. Comput. Sci. Appl., 9, 499-508 (2018).
[17] Liu, L.; De Vel, O.; Han, Q.-L.; Zhang, J.; Xiang, Y. Detecting and Preventing Cyber Insider Threats: A Survey. IEEE Commun. Surv. Tutor., 20, 1397-1417 (2018).
[18] Ullah, F.; Edwards, M.; Ramdhany, R.; Chitchyan, R.; Babar, M.A.; Rashid, A. Data exfiltration: A review of external attack vectors and countermeasures. J. Netw. Comp. Appl., 101, 18-54 (2018).
[19] Ho, S.M.; Kaarst-Brown, M.; Benbasat, I. Trustworthiness Attribution: Inquiry Into Insider Threat Detection. J. Assoc. Inf. Sci. Technol., 69, 271-280 (2018).
[20] Rajamanickam, S. Vollala, S. Amin, R.; Ramasubramanian,N. Insider Attack Protection: Lightweight Password-Based Authentication Techniques Using ECC. IEEE Sys. J. PP, 1-12 (2019).
[21] Li, W.; Meng, W.; Kwok, L.F.; IP, H.H.S. Enhancing collaborative intrusion detection networks against insider attacks using supervised intrusion sensitivity-based trust management model. J. Netw. Comput. Appl., 77, 135-145 (2017).
[22] Callegati, F.; Giallorenzo, S.; Melis, A.; Prandini, M. Cloud-of-Things meets Mobility-as-a-Service: An insider threat perspective. Comput. Secur., 74, 277-295 (2018).
[23] Meryem, A.; Samira, D.; Bouabid, E.O.; Mouad, L. A novel approach in detecting intrusions using NSLKDD database and MapReduce programming. Procedia Comput. Sci., 110, 230-235 (2017).
[24] Lo, O.; Buchanan, W.J.; Griffiths, P.; Macfarlane, R. Distance Measurement Methods for Improved Insider Threat Detection. Secur. Commun. Netw. 2018, 5906368 (2018).
[25] Alizadeh, M.; Lu, X.; Fahland, D.; Zannone, N.; van der Aalst, W.M.P. Linking data and process perspectives for conformance analysis. Comput. Secur. 73, 172-193 (2018).
[26] Harilal, A.; Toffalini, F.; Homoliak, I.; Castellanos, J.H. Twos: A dataset of malicious insider threat behavior based on a gamified competition. J. Wirel. Mob. Netw. (2018) 1.
[27] P. Dhiman, S. K. Henge, “Comparative Analysis of Cloud Security Complexities and Past Proposed Non-Homomorphic and Homomorphic Encryption Methodologies with Limitation” in CRC Press, 4th International Conference on Information and Communication Technology for Competitive Strategies (ICTCS- 2019), pp: 787-799, December 13th-14th (2019).
[28] Dhiman, P., Henge, S.K. Analysis of Blockchain Secure Models and Approaches Based on Various Services in Multi-tenant Environment. In: Singh, P.K., Singh, Y., Chhabra, J.K., Illés, Z., Verma, C. (eds) Recent Innovations in Computing. Lecture Notes in Electrical Engineering, vol 855 (2022). Springer, Singapore. https://doi.org/10.1007/978-981-16-8892-8_42.
[29] ArnauErola, IoannisAgrafiotis, Michael Goldsmith, Sadie Creese, Insider-threat detection: Lessons from deploying the CITD tool in three multinational organisations, Journal of Information Security and Applications, Vol. 67, 2022, 103167, ISSN 2214-2126, https://doi.org/10.1016/j.jisa.2022.103167.
[30] Legg, P. A., Buckley, O., Goldsmith, M., & Creese, S. Automated insider threat detection system using user and role-based profile assessment. IEEE Systems Journal, 11(2), 503-512 (2017). https://doi.org/10.1109/JSYST.2015.2438442.




