摘要
企业组织网络所面临的威胁不仅来自外部,而且也来自内部,而内部威胁(Insider Threat)已被认为是一个非常严重的安全问题。现在,内部威胁分析检测工具方面的研究仍处于探索阶段,笔者提出一种新颖的基于用户操作树的内部威胁检测模型。该模型依据用户对系统的操作,定制生成该用户的操作树,通过分析用户操作树可以预测内部威胁的存在。
Threats that business corporations are facing come from not only the outsider, but also the insider. Nowadays,insider threats are widely recognized as an issue of ulmost importance for security management. However, the development of assessing instrument for discovery and analysis of insider threats is still in an explore stage. The present study provides a novel model for detecting insider threats. This model offers a minimal operation tree on the basis of the specific operation system of the customer. And this model can detect the operation behaviors of the insider in the real time, and make decisions to insider threats.
出处
《河北省科学院学报》
CAS
2008年第1期10-14,共5页
Journal of The Hebei Academy of Sciences