Logo image
A Preliminary Cyber Ontology for Insider Threats in the Financial Sector
Conference proceeding

A Preliminary Cyber Ontology for Insider Threats in the Financial Sector

Gokhan Kul and Shambhu Upadhyaya
Proceedings of the 7th ACM CCS International Workshop on Managing Insider Security Threats, pp.75-78
ACM Conferences
CCS'15: The 22nd ACM Conference on Computer and Communications Security
10/16/2015

Abstract

Security and privacy -- Database and storage security Software and its engineering -- Software notations and tools -- Formal language definitions -- Semantics Theory of computation -- Semantics and reasoning Theory of computation -- Semantics and reasoning -- Program semantics Theory of computation -- Theory and algorithms for application domains -- Database theory -- Theory of database privacy and security
Insider attack has become a major threat in financial sector and is a very serious and pervasive security problem. Currently, there is no insider threat ontology in this domain and such an ontology is critical to developing countermeasures against insider attacks. In this paper, we create an ontology focusing on insider attacks in the banking domain targeting database systems. We define the taxonomy used in this ontology and identify the relationships between the ontology classes. The resulting structure is a domain ontology mapped onto the Suggested Upper Merged Ontology (SUMO), Friend of a Friend(FOAF) and Finance ontologies to make our work integrable to the systems that use these ontologies and to create a broad knowledge base. The attack types we formulate in the ontology are masquerade, privilege elevation, privilege abuse and collusion attacks. Our model could be used to systematically evaluate any insider threat detection schemes in a realistic way and discover attacks that share similarities with previously identified attacks.

Metrics

6 Record Views

Details

Logo image