错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Scheme for Selection of Deceptions as a Countermeasure for Insider Threats

  • Sana Okumura,
  • Tomoya Amagasa,
  • Tsubasa Shibata,
  • Takumi Yamamoto,
  • Tadakazu Yamanaka,
  • Tetsushi Ohki,
  • Masakatsu Nishigaki

摘要

The number of insider threats and the expense of handling them increase every year, rendering it imperative to adopt measures against insider threats. In particular, insiders must adopt a psychological approach. Psychological approaches can be classified into three categories: deceiving insiders, demoralizing insiders, and luring insiders. The deception simultaneously accomplishes these three approaches. The disruption of enterprise systems by deception mechanisms causes a significant decrease in usability for users. The application of deception mechanisms requires careful consideration. Therefore, when designing deception as a countermeasure against insider threats, usability and security must be balanced from the viewpoint of cost-effectiveness. For evaluating cost-effectiveness of security measures, a method that models the relationship between “assets”, “threats”, and “countermeasures” as well as formulates the countermeasure selection problem as a discrete optimization problem has been proposed. However, these methods assume an external intruder, and to the best of our knowledge, no existing research explicitly covers the selection of countermeasures against insiders (malicious insiders). This paper proposes a scheme to quantitatively evaluate the effectiveness of deception against insider threats and determine the optimal deception mechanism. In the existing method, the relationship between “assets”, “threats”, and “countermeasures” is formulated as a discrete optimization problem, but the proposed method explicitly includes insiders as “threats” and deception as “countermeasures”. In addition, when evaluating the effectiveness of insider-threat countermeasures in the model, the usability of users must be considered. Therefore, by adding “operation” to “assets”, “threats”, and “countermeasures”, the proposed method incorporates the impact of selected countermeasures on the “usability” of business into the formulation of existing methods. Specifically, the existing method is sublimated into a security measure selection method that includes insider threat countermeasures (deceptions) by formulating the objective function of the existing method to be maximized with “usability” as a constraint.