About Us Our Work Employment News & Events
MITRE Remote Access for MITRE Staff and Partners Site Map
Our Work

Follow Us:

Visit MITRE on Facebook
Visit MITRE on Twitter
Visit MITRE on Linkedin
Visit MITRE on YouTube
View MITRE's RSS Feeds
View MITRE's Mobile Apps
Home > Our Work > Technical Papers >

Analysis and Detection of Malicious Insiders

March 2005

Mark Maybury, The MITRE Corporation
Penny Chase, The MITRE Corporation
Brant Cheikes, The MITRE Corporation
Dick Brackney, Advanced Research and Development Activity in Information Technology
Sara Matzner, University of Texas
Tom Hetherington, University of Texas
Brad Wood, BBN Technologies
Conner Sibley, BBN Technologies
Jack Marin, BBN Technologies
Tom Longstaff, Carnegie Mellon University
Lance Spitzner, Honey Net Consortium
Jed Haile, Honey Net Consortium
John Copeland, Georgia Institute of Technology
Scott Lewandowski, MIT Lincoln Laboratory

ABSTRACT

This paper summarizes a collaborative, six month ARDA NRRC1 challenge workshop to characterize and create analysis methods to counter sophisticated malicious insiders in the United States Intelligence Community. Based upon a careful study of past and projected cases, we report a generic model of malicious insider behaviors, distinguishing motives, (cyber and organizaphysical) actions, and associated observables. The paper outlines several prototype techniques developed to provide early warning of insider activity, including novel algorithms for structured analysis and data fusion. We report the assessment of their performance in an operational network against three distinct classes of human insiders (an analyst, application administrator, and system administrator), measuring timeliness and accuracy of detection.

View/Download Document

Additional Search Keywords

insider threat, malicious insider, information assurance, cyber indications and warning, observables taxonomy, assets, data fusion, attack graphs, honeypots, StealthWatch, Robert Hanssen

 

Page last updated: April 13, 2005   |   Top of page

Homeland Security Center Center for Enterprise Modernization Command, Control, Communications and Intelligence Center Center for Advanced Aviation System Development

 
 
 

Solutions That Make a Difference.®
Copyright © 1997-2013, The MITRE Corporation. All rights reserved.
MITRE is a registered trademark of The MITRE Corporation.
Material on this site may be copied and distributed with permission only.

IDG's Computerworld Names MITRE a "Best Place to Work in IT" for Eighth Straight Year The Boston Globe Ranks MITRE Number 6 Top Place to Work Fast Company Names MITRE One of the "World's 50 Most Innovative Companies"
 

Privacy Policy | Contact Us