An Insider Threat Resilient Framework Based on Honey Traps in a Function-Based Access Control Environment
摘要
Insider threats present a formidable security challenge in corporate environments, distinct from external threats due to insiders’ intricate knowledge of an organization’s access infrastructure, policies, and scheduling. The complexity, time, and expertise required to detect, model, and timestamp insider threats render them especially challenging to mitigate. While various strategies to counter insider threats have been proposed, our research introduces a novel approach to counter insider threats by combining Function-Based Access Control (FBAC) with honey traps, enhancing our capability to proactively identify and monitor potential insider threats. The incorporation of the Honey Trap Factor (H) allows us to quantify the effectiveness of our honey traps in a novel manner. The rigorous evaluation of our approach demonstrates its ability to detect correlated attributes and adapt policy sets, marking a substantial step forward in proactive insider threat detection and mitigation.