Monitoring Systems White Papers
Correlating SIM Information to Detect Insider Threats
Overview
Not a week goes by without the report of a security breach committed by an employee or contractor of an organization. According to studies by the United States Secret Service and CERT, approximately 80% of insiders who launched attacks on their companies had exhibited negative behaviors before the incident and 92% had experienced a negative work-related event, such as a demotion, transfer, warning or termination. At the time of the incident, 59% were former employees or contractors, while 41% were still employees.
This SANS paper examines how the most common attacks can be detected by the deliberate examination of data found in system log files. While the bulk of the event data found in logs is difficult to capture, retain and examine, there is a class of software solutions that are focused on producing information that can assist an organization in detecting suspicious and unauthorized activity.
Download this informative whitepaper to learn more on how to detect insider threats.
| Publisher | SenSage | File Format | |
|---|---|---|---|
| Date Published | July 2007 | ||
| Format | White Papers | ||
| Topics | |||



