Trapping Malicious Insiders in the SPDR Web

HICSS(2009)

引用 5|浏览28
暂无评分
摘要
The insider threat has assumed increasing importance as our dependence on critical cyber information infrastructure has increased. In this paper we describe an approach for thwarting and attributing insider attacks. The Sense, Prepare, Detect, and React (SPDR) approach utilizes both a highly intelligent software reasoning system to anticipate, recognize, respond to, and attribute attacks as well as a widely distributed set of hardware-based sensor-effectors to provide alerts used by the reasoning system and to implement responses as directed by it. Using hardware sensor-effectors greatly reduces the risk that a savvy malicious insider can bypass or cripple the system's monitoring and control capabilities. In this paper we describe the prototype SPDR system and the results of its successful evaluation by an independent, DARPA-sponsored Red Team. We conclude with thoughts on possible SPDR enhancements and further research.
更多
查看译文
关键词
hardware-based sensor-effectors,insider threat,darpa-sponsored red team,cyber information,computer crime,savvy malicious insider,intelligent software reasoning system,reasoning system,insider attack,malicious insiders,prototype spdr system,spdr web,internet,approach utilizes,possible spdr enhancement,information infrastructure
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要