Using Alternate Reality Games To Find A Needle In A Haystack: An Approach For Testing Insider Threat Detection Methods

Shannon Wasko,Rebecca E. Rhodes, Megan Goforth,Nathan Bos,Hannah P. Cowley,Gerald Matthews, Alice Leung, Satish Iyengar,Jonathon Kopecky

COMPUTERS & SECURITY(2021)

引用 5|浏览10
暂无评分
摘要
Insider threats are individuals who pose significant security risks but are difficult to identify with traditional methods that rely on passively collected data. Recently, active indicators have been developed as a more active monitoring method designed to evoke differential behaviors in insider threats and benign employees. While these methods have shown promise, it is unclear how well they can work in real-world office settings. In this experiment, we tested three classes of email-based active indicators in an alternate reality game to assess their ability to differentiate insiders from benign employees in a realistic setting. Participants took turns playing the role of a benign employee and an insider threat in an immersive, realistic environment and were exposed to active indicators under both scenarios. The active indicators were designed to elicit the following behaviors from participants acting as insider threats: exploit opportunities to gather information, avoid accidental or inadvertent discovery, or maintain hypervigilant security awareness. The alternate reality game was successful in creating a highly engaging environment with high ecological validity. Active indicators that revealed opportunities to gather desirable information were most effective; participants acting as insider threats were significantly more likely to engage in the characteristic behavior (e.g. apply for an administrative position to get additional access) than participants acting as benign employees for most of the active indicators in this class. Our results suggest that active indicators can be tested with alternate reality games to help estimate their effectiveness in realistic, noisy environments. The finding that some types of active indicators could identify insider threats in a setting where participants had significant latitude for how they could respond suggests promise for using active indicators in real-world work environments.(c) 2021 Elsevier Ltd. All rights reserved.
更多
查看译文
关键词
Insider threat, active indicator, alternate reality game, behavioral research, national security
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要