skip to main content
10.1145/1185448.1185638acmotherconferencesArticle/Chapter ViewAbstractPublication Pagesacm-seConference Proceedingsconference-collections
Article

Applying role based access control and genetic algorithms to insider threat detection

Published:10 March 2006Publication History

ABSTRACT

An insider threat is caused by authorized users potentially performing unsanctioned or inappropriate actions that endanger the computer security of an organization. This paper describes a novel approach that employs the ideas of Role-Based Access Control (RBAC) to initiate role-action mapping rules in line with organization specific security policies. These rules can be refined by genetic algorithms (GAs) to identify discrepancies between user roles and processes.

References

  1. E. Bertino, A. Kamra, E. Terzi, and A. Vakali, "Intrusion Detection in RBAC-administered Databases," CERIAS TR 2005--70, 2005.Google ScholarGoogle Scholar
  2. P. G. Bradford, M. Brown, J. Perdue, and B. Self, "Towards Proactive Computer-System Forensics," Proc. of International Conference on Information Technology: Coding and Computing, Vol. 2, 2004 (ITCC 2004), 648--652. Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. P. G. Bradford and N. Hu, "A Layered Approach to Insider Threat Detection and Proactive Forensics," Annual Computer Security Applications Conference (ACSAC), Technology Blitz, Dec. 2005, Tucson, AZ.Google ScholarGoogle Scholar
  4. D. Ferraiolo and R. Kuhn, "Role-Based Access Controls," Proc. of the 15th National Computer Security Conference, Oct. 1992, 554--563.Google ScholarGoogle Scholar
  5. J. H. Holland, "Genetic Algorithms and the Optimal Allcation of Trials," SIAM Journal on Computing, Vol. 2, No. 2, 88--105, 1973.Google ScholarGoogle ScholarCross RefCross Ref
  6. R. Sandhu, D. Ferraiolo, and R. Kuhn, "The NIST Model for Role-Based Access Control: Towards a Unified Standard," Proc. of the 5th ACM Workshop on Role Based Access Control, July 26--27, 2000. Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. Applying role based access control and genetic algorithms to insider threat detection

          Recommendations

          Comments

          Login options

          Check if you have access through your login credentials or your institution to get full access on this article.

          Sign in
          • Published in

            cover image ACM Other conferences
            ACM-SE 44: Proceedings of the 44th annual Southeast regional conference
            March 2006
            823 pages
            ISBN:1595933158
            DOI:10.1145/1185448

            Copyright © 2006 ACM

            Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

            Publisher

            Association for Computing Machinery

            New York, NY, United States

            Publication History

            • Published: 10 March 2006

            Permissions

            Request permissions about this article.

            Request Permissions

            Check for updates

            Qualifiers

            • Article

            Acceptance Rates

            Overall Acceptance Rate178of377submissions,47%

          PDF Format

          View or Download as a PDF file.

          PDF

          eReader

          View online with eReader.

          eReader