Skip to main content

Research Repository

See what's under the surface

Visualizing the insider threat: Challenges and tools for identifying malicious user activity

Legg, Philip

Authors

Phil Legg Phil.Legg@uwe.ac.uk
Associate Professor in Cyber Security



Abstract

One of the greatest challenges for managing organisational cyber security is the threat that comes from those who operate within the organisation. With entitled access and knowledge of organisational processes, insiders who choose to attack have the potential to cause serious impact, such as financial loss, reputational damage, and in severe cases, could even threaten the existence of the organisation. Security analysts therefore require sophisticated tools that allow them to explore and identify user activity that could be in- dicative of an imminent threat to the organisation. In this work, we discuss the challenges associated with identifying insider threat activity, along with the tools that can help to combat this problem. We present a visual analytics approach that incorporates multiple views, including a user selection tool that indicates anomalous behaviour, an interactive Principal Component Analysis (iPCA) tool that aids the analyst to assess the reasoning behind the anomaly detection results, and an activity plot that visualizes user and role activity over time. We demonstrate our approach using the Carnegie Mellon University CERT Insider Threat Dataset to show how the visual analytics workflow supports the Information-Seeking mantra.

Presentation Conference Type Conference Paper (unpublished)
Start Date Oct 26, 2015
Publication Date Oct 26, 2015
Journal IEEE Symposium on Visualization for Cyber Security
Peer Reviewed Peer Reviewed
APA6 Citation Legg, P. (2015, October). Visualizing the insider threat: Challenges and tools for identifying malicious user activity. Paper presented at IEEE Symposium on Visualization for Cyber Security
Keywords insider threat, behavioural analysis, model visualization
Publisher URL http://dx.doi.org/10.1109/VIZSEC.2015.7312772
Related Public URLs http://www.vizsec.org
Additional Information Title of Conference or Conference Proceedings : IEEE Symposium on Visualization for Cyber Security

Files





You might also like



Downloadable Citations