2018 IEEE Security and Privacy Workshops (SPW) 2018
DOI: 10.1109/spw.2018.00035
|View full text |Cite
|
Sign up to set email alerts
|

SOFIT: Sociotechnical and Organizational Factors for Insider Threat

Abstract: Human behavioral factors have been insufficiently represented in structured models (e.g., ontology frameworks) of insider threat risk. This paper describes the design and development of a structured model that emphasizes individual and organizational sociotechnical factors while incorporating technical indicators from previous work. We compare this model with previous research and describe a use case to demonstrate how the model can be applied as an ontology. We also summarize results of an expert knowledge el… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

1
36
0
1

Year Published

2018
2018
2023
2023

Publication Types

Select...
6
2

Relationship

2
6

Authors

Journals

citations
Cited by 27 publications
(38 citation statements)
references
References 30 publications
1
36
0
1
Order By: Relevance
“…Recognizing target threat behaviors is therefore a complex, model-based classification process that involves inferences about multifaceted combinations or sequences of behavioral, psychological, and technical indicators. This interpretation of the threat assessment process provides a key rationale for related modeling efforts and the design of expert knowledge elicitation studies initially reported in [6] and [7] and extended here.…”
Section: General Modelmentioning
confidence: 70%
See 2 more Smart Citations
“…Recognizing target threat behaviors is therefore a complex, model-based classification process that involves inferences about multifaceted combinations or sequences of behavioral, psychological, and technical indicators. This interpretation of the threat assessment process provides a key rationale for related modeling efforts and the design of expert knowledge elicitation studies initially reported in [6] and [7] and extended here.…”
Section: General Modelmentioning
confidence: 70%
“…This paper describes continuing work on a comprehensive insider threat ontology [6] [7] that supports research to develop more effective decision support tools, facilitates insider threat program evaluation s, and promotes understanding of the complex insider threat domain. A hallmark of the ontology-called Sociotechnical and Organizational Factors for Insider Threat (SOFIT)-is the inclusion of behavioral, social, and organizational factors in addition to the cyber/technical factors traditionally identified with insider threat risk.…”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation
“…客观要素方面通过采集命令执行、网络访问、文件操作和鼠标键盘使用等数据中的内部人 员行为痕迹, 运用数据挖掘算法分析人员行为特征, 检测并预防内部威胁. 大数据环境下, 为精准刻画人员特征, 提升内部威胁检测的正确率, 需要扩大数据采集的深度和 广度, 并且对主客观要素进行联合分析 [332] , 在 Greitzer 等 [333] 最新的研究成果中, 甚至将分析对象的 心理、行为等个人因素进一步扩展到组织因素. 高效的海量数据处理、内部威胁特征分析和精确的内 部威胁检测还需要大数据技术的支持.…”
Section: 基于大数据技术的服务与平台安全监管unclassified
“…In addition, Capelli et al [18] indicate that non-technical and technical indicators are equally important to insider threat detection and prevention. Recent work [19] introduced SOFIT, a knowledge base (ontology) of individual and organizational sociotechnical factors for insider threats that expands on ITIO [20] (ontology that focuses on describing technical/cyber events). The authors demonstrated through a use case that non-technical indicators can enhance proactive insider threat mitigation.…”
Section: Introductionmentioning
confidence: 99%