Insider Threat Control: Using Centralized Logging to Detect Data Exfiltration Near Insider Termination

Since 2001, the CERT Insider Threat Center has built an extensive library and comprehensive database containing more than 600 cases of crimes committed against organizations by insiders. A significant class of insider crimes, insider theft of intellectual property, involves highly damaging attacks against organizations that result in significant tangible losses in the form of stolen business plans, customer lists, and other proprietary information. The Insider Threat Center's behavioral modeling of insiders who steal intellectual property shows that many insiders who stole their organization's intellectual property stole at least some of it within 30 days of their termination. This technical note presents an example of an insider threat pattern based on this insight. It then presents an example implementation of this pattern on an enterprise-class system using the centralized log storage and indexing engine Splunk to detect malicious insider behavior on a network.

PDF [305 KB]

Authors

Michael Hanley

Joji Montelibano

This report is related to the following area(s) of work:

Security and Survivability

Technical Note
CMU/SEI-2011-TN-024
October 2011

Cite This Report

SEI:

Hanley, Michael; & Montelibano, Joji. Insider Threat Control: Using Centralized Logging to Detect Data Exfiltration Near Insider Termination (CMU/SEI-2011-TN-024). Software Engineering Institute, Carnegie Mellon University, 2011. http://www.sei.cmu.edu/library/abstracts/reports/11tn024.cfm

IEEE:

M. Hanley, and J. Montelibano, "Insider Threat Control: Using Centralized Logging to Detect Data Exfiltration Near Insider Termination," Software Engineering Institute, Carnegie Mellon University, Pittsburgh, Pennsylvania, Technical Note CMU/SEI-2011-TN-024, 2011. http://www.sei.cmu.edu/library/abstracts/reports/11tn024.cfm

APA:

Hanley, M., & Montelibano, J. (2011) . Insider Threat Control: Using Centralized Logging to Detect Data Exfiltration Near Insider Termination (CMU/SEI-2011-TN-024). Retrieved May 23, 2012, from the Software Engineering Institute, Carnegie Mellon University website: http://www.sei.cmu.edu/library/abstracts/reports/11tn024.cfm

CHI:

Hanley, Michael, and Joji Montelibano. Insider Threat Control: Using Centralized Logging to Detect Data Exfiltration Near Insider Termination (CMU/SEI-2011-TN-024). Pittsburgh, PA: Software Engineering Insitute, Carnegie Mellon University, 2011. http://www.sei.cmu.edu/library/abstracts/reports/11tn024.cfm

MLA:

Hanley, M., & Montelibano, J. 2011. Insider Threat Control: Using Centralized Logging to Detect Data Exfiltration Near Insider Termination (Technical Report CMU/SEI-2011-TN-024). Pittsburgh: Software Engineering Insitute, Carnegie Mellon University. http://www.sei.cmu.edu/library/abstracts/reports/11tn024.cfm

Find Us Here

Share This Page

Share on Facebook  Send to your Twitter page  Save to del.ico.us  Save to LinkedIn  Digg this  Stumble this page.  Add to Technorati favorites  Save this page on your Google Home Page 

For more information

Contact Us

info@sei.cmu.edu

412-268-5800