Affiliation:
1. Sandia National Laboratories
2. University of Texas, Nuclear Engineering Teaching Laboratory
Abstract
Advances on differentiating between malicious intent and natural “organizational evolution” to explain observed anomalies in operational workplace patterns suggest benefit from evaluating collective behaviors observed in the facilities to improve
insider threat detection and mitigation (ITDM).
Advances in
artificial neural networks (ANN)
provide more robust pathways for capturing, analyzing, and collating disparate data signals into quantitative descriptions of operational workplace patterns. In response, a joint study by Sandia National Laboratories and the University of Texas at Austin explored the effectiveness of commercial artificial neural network (ANN) software to improve ITDM. This research demonstrates the benefit of learning patterns of organizational behaviors, detecting off-normal (or anomalous) deviations from these patterns, and alerting when certain types, frequencies, or quantities of deviations emerge for improving ITDM. Evaluating nearly 33,000 access control data points and over 1,600 intrusion sensor data points collected over a nearly twelve-month period, this study's results demonstrated the ANN could recognize operational patterns at the Nuclear Engineering Teaching Laboratory (NETL) and detect off-normal behaviors—suggesting that ANNs can be used to support a data-analytic approach to ITDM. Several representative experiments were conducted to further evaluate these conclusions, with the resultant insights supporting collective behavior-based analytical approaches to quantitatively describe insider threat detection and mitigation.
Publisher
Association for Computing Machinery (ACM)
Reference31 articles.
1. Federal Register Vol. 76 No. 198. 2011. Presidential documents. Retrieved from https://www.dni.gov/files/NCSC/documents/nittf/EO_13587.pdf.
2. International Atomic Energy Agency. 2008. Preventive and Protective Measures Against Insider Threats . IAEA Nuclear Security Series No. 8: Implementing Guide.
3. World Institute for Nuclear Security. 2018. Countering Violent Extremism and Insider Threats in the Nuclear Sector .
Cited by
5 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献