Skip to main content
QUICK REVIEW

[论文解读] Insider threats in Cyber Security: The enemy within the gates

Guerrino Mazzarolo, Anca Delia Jurcut|arXiv (Cornell University)|Nov 21, 2019
Information and Cyber Security参考文献 1被引用 14
一句话总结

本文提出了一套全面的内部威胁管理计划框架,旨在预防、检测和应对组织中的恶意及非故意内部威胁。该框架由首席信息安全官(CISO)牵头,联合人力资源(HR)、法务和网络安全团队,强调文化变革与跨职能协作,以防范内部风险对关键数据的威胁。

ABSTRACT

Insider threats have become reality for civilian firms such as Tesla, which experienced sabotage and intellectual property theft, and Capital One, which suffered from fraud. Even greater social impact was caused by the data breach at the US Department of Defense, perpetrated by well-known attackers Chelsea Manning and Edward Snowden, whose espionage and hacktivist activities are widely known. The dramatic increase of such incidents in recent years and the incalculable damage committed by insiders must serve as a warning for all members of the cyber security community. It is no longer acceptable to continue to underestimate the problem of insider threats. Firms, organizations, institutions and governments need to lead and embrace a cultural change in their security posture. Through the adoption of an Insider Threat Program that engages all the strategic branches (including HR, Legal, Information Assurance, Cyber Security and Intelligence), coordinated by the chief information security officer and supported by c-level executive, it is possible to implement a framework that can prevent, detect, and respond to disloyal and/or unintentional insider threats. Hence, defending your enterprise from insider threats is a vital part of information security best practices. It is essential that your company highly valuable classified data and assets are protected from its greatest threat: the enemy within the gates.

研究动机与目标

  • 应对民用和政府组织中日益严峻的内部攻击威胁,典型案例包括特斯拉、Capital One和国防部(DoD)的事件。
  • 突出内部威胁的严重后果,包括破坏、数据窃取和间谍活动,如切莉·曼宁(Chelsea Manning)和爱德华·斯诺登(Edward Snowden)的真实案例所示。
  • 倡导网络安全姿态的文化转型,超越单纯的技术控制,纳入组织与人为因素。
  • 提出由CISO领导、整合人力资源、法务、信息保障和网络安全团队的协调性、全企业范围的计划。
  • 建立由C级高管支持的治理模式,将内部威胁管理制度化为一项核心安全实践。

提出的方法

  • 构建一个整合战略、运营和技术组件的综合性内部威胁框架,覆盖组织内各职能部门。
  • 通过首席信息安全官(CISO)协调项目,确保与企业风险和合规目标保持一致。
  • 通过共享责任和明确角色,推动人力资源、法务、网络安全、情报和信息保障等多部门协作。
  • 实施基于行为分析和异常监控的检测机制,识别恶意及非故意的内部活动。
  • 建立响应协议,实现对内部事件的快速遏制与补救,包括取证调查和法律行动。
  • 通过培训、意识提升和持续监控,将该计划融入组织文化,以维持长期有效性。

实验结果

研究问题

  • RQ1组织如何有效检测和响应绕过传统边界防护控制的内部威胁?
  • RQ2在多样化的企业职能中,哪些组织架构和治理模式最能有效缓解内部威胁?
  • RQ3C级高管与CISO如何协作,将内部威胁管理确立为战略优先事项?
  • RQ4人力资源和法务等非技术部门在预防和应对内部威胁中发挥什么作用?
  • RQ5组织内部的文化变革在不损害员工信任或隐私的前提下,如何降低内部威胁风险?

主要发现

  • 内部威胁对组织构成重大且持续增长的风险,特斯拉、Capital One和美国国防部(US Department of Defense)的真实事件表明其可能造成严重运营和声誉损害。
  • 最具破坏性的内部威胁事件通常涉及拥有合法访问权限的人员,如切莉·曼宁和爱德华·斯诺登的间谍行为,凸显了内部监控和访问控制的必要性。
  • 由人力资源、法务和网络安全团队共同参与的协调性内部威胁管理计划,显著提升了检测与响应能力,优于孤立的技术措施。
  • C级高管的支持与CISO主导的协调机制,对于将内部威胁管理融入组织文化并确保持续投入至关重要。
  • 该框架通过结合技术监控与人为及流程控制,使组织能够主动预防内部威胁。
  • 本文结论指出,保护机密和高价值数据需要将内部威胁视为战略优先事项,而不仅限于技术层面。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。