TARU PUBLICATIONS
Journal of Discrete Mathematical Sciences and Cryptography cover
Open Access ·Peer-reviewed·ISSN (Online): 2169-0065·ISSN (Print): 0972-0529

Monthly Journal: Publishes theoretical and applied research in all areas of Discrete Mathematical Sciences, Cryptography, Combinatorics, Elliptic Curves and Information Security.

Issues up to 2022 co-published with and available at:Taylor & Francis Online
submissions@tarupublications.com
Open Access Research Article

Analysis and detection of insider attacks using behaviour rule based architecture in enterprise multitenancy

, , , , , *

* Corresponding author · click or hover a name for details

pp. 707–718Vol. 26Issue 3April 2023DOI: 10.47974/JDMSC-1743 Crossmark XML
Published Online:
01 Apr 2023
Article type:
Research Article
Language:
EN
Article no.:
JDMSC-1743
Pages:
707–718

Abstract

The enterprise level data security and privacy are one of the focal key challenges to the pr enterprise and security companies to prevent private data from outside and inside attacks. The insider threats and attacks can pretense a real defense risk to the various internal multi-tenants of various enterprises and companies. The data thievery by insiders of the companies is as a great deal the consequence of enterprises failing to execute the scheme and expertise to member of staff supervise activities and administrate the authenticated data-access to data as it the authentic spiteful activities of member of staff looking for economic benefits in multi-tenancy environment. This research composed with three major objectives: Description of insider attack causes with their impact factors; Implications of behavior rule-based architecture in enterprise multitenancy; Integration of behavior rules with prevention thresholds to control user accessibility for prevention of insider attacks and threats; This paper has described the efficient security scenario to avoid insider attaching complexities. This research is more helping the cyber security experts and network administrators to reduce the insider attacks by building the efficient monitoring intelligent system. The experimental scenarios built with125 authenticated, 29 non-authenticated internal users, and 62 authenticated, 18 non-authenticated external users of single enterprise level and avoided insider attacks and threats.

Keywords

Subject Classifications

Primary 68M25Secondary 68P2568P27

References

[1] Jeremy, Understanding the “Insider Threat” https://cloudtweaks.com/2015/01/4-different-types-attacks-understanding-insider-threat/.
[2] Understanding Insider Threat: A Framework for Characterising
Attacks, http://ieeexplore.ieee.org/document/6957307/?reload=true.
[3] Jason R.C. Nurse,, Oliver Buckley, Philip A. Legg, Michael Goldsmith, Sadie Creese, Gordon R.T. Wright, Monica Whitty, Understanding Insider Threat: A Framework for Characterising Attacks, 2014 IEEE Security and Privacy Workshops. http://www.ieee-security.org/TC/SPW2014/papers/5103a214.PDF.
[4] J. Lee, A. Alghamdi and A. K. Zaidi, “Creating a Digital Twin of an Insider Threat Detection Enterprise Using Model-Based Systems Engineering,” 2022 IEEE International Systems Conference (SysCon), 2022, pp. 1-7, doi: 10.1109/SysCon53536.2022.9773890.
[5] B. Bowen, M. Ben Salem, S. Hershkop, A. Keromytis and S. Stolfo, “Designing Host and Network Sensors to Mitigate the Insider
Threat,” in IEEE Security & Privacy, vol. 7, no. 6, pp. 22-29 (Nov.-Dec. 2009), doi: 10.1109/MSP.2009.109.
[6] P. Dhiman, S. K. Henge, S. Singh, A. Kaur, P. Singh et al., “Blockchain merkle-tree ethereum approach in enterprise multitenant cloud environment,” Computers, Materials & Continua, vol. 74, no.2, pp. 3297–3313 (2023).
[7] Dhiman, P.; Henge, S.K.; Ramalingam, R.; Dumka, A.; Singh, R.; Gehlot, A.; Rashid, M.; Alshamrani, S.S.; AlGhamdi, A.S.; Alshehri, A. Secure Token–Key Implications in an Enterprise Multi-Tenancy Environment Using BGV–EHC Hybrid Homomorphic Encryption. Electronics 2022, 11, 1942. https://doi.org/10.3390/electronics11131942.
[8] Alaa Alsaeed, Combating Insider Threats to Enterprise, https://www.academia.edu/37765548/Combating_Insider_Threats_to_Enterprise.
[9] Dou, Z., Khalil, I., Khreishah, A. and Al-Fuqaha, A., 2017. Robust insider attacks countermeasure for Hadoop: Design and implementation. IEEE Systems Journal.
[10] Li, W., Meng, W. and Horace, H.S., Enhancing collaborative intrusion detection networks against insider attacks using supervised intrusion sensitivity-based trust management model. Journal of Network and Computer Applications, 77, pp.135-145 (2017).
[11] Roy P. and Mazumdar C.. Modelling of Enterprise Insider Threats. DOI: 10.5220/0005327901320136 In Proceedings of the 1st International Conference on Information Systems Security and Privacy (ICISSP-2015), pages 132-136 ISBN: 978-989-758-081-9.
[12] Al-Mhiqani MN, Ahmad R, Zainal Abidin Z, Yassin W, Hassan A, Abdulkareem KH, Ali NS, Yunos Z. A Review of Insider Threat Detection: Classification, Machine Learning Techniques, Datasets, Open Challenges, and Recommendations. Applied Sciences. 2020; 10(15) : 5208. https://doi.org/10.3390/app10155208.
[13] Walker-Roberts, S.; Hammoudeh, M.; Dehghantanha, A. A Systematic Review of the Availability and Efficacy of Countermeasures to Internal Threats in Healthcare Critical Infrastructure. IEEE Access 2018, 6, 25167-25177.
[14] Nasr, P.M.; Yazdian-Varjani, A. Toward Operator Access Management in SCADA System: Deontological Threats Mitigation. IEEE Trans. Ind. Inform. 14, 3314-3324 (2017).
[15] Pitropakis, N.; Lambrinoudakis, C.; Geneiatakis, D. Till All Are One: Towards a Unified Cloud IDS. In Proceedings of the Trust, Privacy and Security in Digital Business; Fischer Hubner, S., Lambrinoudakis, C., Lopez, J., Eds.; Springer: New York, NY, USA, pp. 136-149 (2015).
[16] Al-Mhiqani, M.N.; Ahmad, R.; Yassin, W.; Hassan, A.; Abidin, Z.Z.; Ali, N.S.; Abdulkareem, K.H. Cyber-Security Incidents: A Review Cases in Cyber-Physical Systems. Int. J. Adv. Comput. Sci. Appl., 9, 499-508 (2018).
[17] Liu, L.; De Vel, O.; Han, Q.-L.; Zhang, J.; Xiang, Y. Detecting and Preventing Cyber Insider Threats: A Survey. IEEE Commun. Surv. Tutor., 20, 1397-1417 (2018).
[18] Ullah, F.; Edwards, M.; Ramdhany, R.; Chitchyan, R.; Babar, M.A.; Rashid, A. Data exfiltration: A review of external attack vectors and countermeasures. J. Netw. Comp. Appl., 101, 18-54 (2018).
[19] Ho, S.M.; Kaarst-Brown, M.; Benbasat, I. Trustworthiness Attribution: Inquiry Into Insider Threat Detection. J. Assoc. Inf. Sci. Technol., 69, 271-280 (2018).
[20] Rajamanickam, S. Vollala, S. Amin, R.; Ramasubramanian,N. Insider Attack Protection: Lightweight Password-Based Authentication Techniques Using ECC. IEEE Sys. J. PP, 1-12 (2019).
[21] Li, W.; Meng, W.; Kwok, L.F.; IP, H.H.S. Enhancing collaborative intrusion detection networks against insider attacks using supervised intrusion sensitivity-based trust management model. J. Netw. Comput. Appl., 77, 135-145 (2017).
[22] Callegati, F.; Giallorenzo, S.; Melis, A.; Prandini, M. Cloud-of-Things meets Mobility-as-a-Service: An insider threat perspective. Comput. Secur., 74, 277-295 (2018).
[23] Meryem, A.; Samira, D.; Bouabid, E.O.; Mouad, L. A novel approach in detecting intrusions using NSLKDD database and MapReduce programming. Procedia Comput. Sci., 110, 230-235 (2017).
[24] Lo, O.; Buchanan, W.J.; Griffiths, P.; Macfarlane, R. Distance Measurement Methods for Improved Insider Threat Detection. Secur. Commun. Netw. 2018, 5906368 (2018).
[25] Alizadeh, M.; Lu, X.; Fahland, D.; Zannone, N.; van der Aalst, W.M.P. Linking data and process perspectives for conformance analysis. Comput. Secur. 73, 172-193 (2018).
[26] Harilal, A.; Toffalini, F.; Homoliak, I.; Castellanos, J.H. Twos: A dataset of malicious insider threat behavior based on a gamified competition. J. Wirel. Mob. Netw. (2018) 1.
[27] P. Dhiman, S. K. Henge, “Comparative Analysis of Cloud Security Complexities and Past Proposed Non-Homomorphic and Homomorphic Encryption Methodologies with Limitation” in CRC Press, 4th International Conference on Information and Communication Technology for Competitive Strategies (ICTCS- 2019), pp: 787-799, December 13th-14th (2019).
[28] Dhiman, P., Henge, S.K. Analysis of Blockchain Secure Models and Approaches Based on Various Services in Multi-tenant Environment. In: Singh, P.K., Singh, Y., Chhabra, J.K., Illés, Z., Verma, C. (eds) Recent Innovations in Computing. Lecture Notes in Electrical Engineering, vol 855 (2022). Springer, Singapore. https://doi.org/10.1007/978-981-16-8892-8_42.
[29] ArnauErola, IoannisAgrafiotis, Michael Goldsmith, Sadie Creese, Insider-threat detection: Lessons from deploying the CITD tool in three multinational organisations, Journal of Information Security and Applications, Vol. 67, 2022, 103167, ISSN 2214-2126, https://doi.org/10.1016/j.jisa.2022.103167.
[30] Legg, P. A., Buckley, O., Goldsmith, M., & Creese, S. Automated insider threat detection system using user and role-based profile assessment. IEEE Systems Journal, 11(2), 503-512 (2017). https://doi.org/10.1109/JSYST.2015.2438442.

Views: 352Downloads: 4Citations: 2