{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/16177"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/16177","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Insider threat simulation and performance analysis of insider detection algorithms with role based models","abstract":"Insider threat problems are widespread in industry today. They have resulted in huge losses to organizations. The security reports by leading organizations point out the fact that there have been many more insider attacks in recent years than any other form of attack. Detection of these insider threats is a top priority. One problem facing the detection mechanisms is that the real data for modeling is not easily available. This thesis describes a simulator which can simulate the insiders and generate access information in the form of logs. Currently there are many methods which use data mining algorithms to detect insider attacks. Role based detection is a well known mechanism to accurately distinguish insider behavior from the normal behavior. The thesis focuses on the advantages of using role based mechanisms for insider threat detection. Five algorithms have been chosen and performance analysis of these under various scenarios is carried out. The thesis discusses these results in detail. The simulator is built on the Scalable Simulation Framework (SSF). It is an extension of the Boeing simulator, JANUS. The simulator uses behavior files to model an insider/normal user and generates the access information using Markov chains.","abstract_html":"Insider threat problems are widespread in industry today. They have resulted in huge losses to organizations. The security reports by leading organizations point out the fact that there have been many more insider attacks in recent years than any other form of attack. Detection of these insider threats is a top priority. One problem facing the detection mechanisms is that the real data for modeling is not easily available. This thesis describes a simulator which can simulate the insiders and generate access information in the form of logs. Currently there are many methods which use data mining algorithms to detect insider attacks. Role based detection is a well known mechanism to accurately distinguish insider behavior from the normal behavior. The thesis focuses on the advantages of using role based mechanisms for insider threat detection. Five algorithms have been chosen and performance analysis of these under various scenarios is carried out. The thesis discusses these results in detail. The simulator is built on the Scalable Simulation Framework (SSF). It is an extension of the Boeing simulator, JANUS. The simulator uses behavior files to model an insider/normal user and generates the access information using Markov chains.","abstract_has_math":false,"creators":["Nellikar, Suraj"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Nicol, David M."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2010,"date_issued":"2010-05-19T18:39:53Z","date_published":"2010-05-19T18:39:53Z","updated_at":"2026-07-22T22:25:08Z","subjects":["Insider threat","Insider detection algorithms","Role-based access control"],"languages":["en"],"rights":["Copyright 2010 Suraj Nellikar"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/16177","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Nicol, David M."]},{"key":"dc:creator","label":"Author","values":["Nellikar, Suraj"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2010-05-19T18:39:53Z","2010-5"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Insider threat","Insider detection algorithms","Role-based access control"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2010 Suraj Nellikar"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/16177"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Insider threat problems are widespread in industry today. They have resulted in huge losses to organizations. The security reports by leading organizations point out the fact that there have been many more insider attacks in recent years than any other form of attack. Detection of these insider threats is a top priority. One problem facing the detection mechanisms is that the real data for modeling is not easily available. This thesis describes a simulator which can simulate the insiders and generate access information in the form of logs. Currently there are many methods which use data mining algorithms to detect insider attacks. Role based detection is a well known mechanism to accurately distinguish insider behavior from the normal behavior. The thesis focuses on the advantages of using role based mechanisms for insider threat detection. Five algorithms have been chosen and performance analysis of these under various scenarios is carried out. The thesis discusses these results in detail. The simulator is built on the Scalable Simulation Framework (SSF). It is an extension of the Boeing simulator, JANUS. The simulator uses behavior files to model an insider/normal user and generates the access information using Markov chains.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2010-04-27T21:08:44Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 2 Nellikar_Suraj.doc: 1567744 bytes, checksum: 4a130af31f941d4b6ba383daf28cbf9a (MD5) Nellikar_Suraj.pdf: 1322399 bytes, checksum: 5bbe62233246b6f8243c424518cfa684 (MD5)","Made available in DSpace on 2010-05-19T18:39:53Z (GMT). No. of bitstreams: 3 Nellikar_Suraj.doc: 1567744 bytes, checksum: 4a130af31f941d4b6ba383daf28cbf9a (MD5) Nellikar_Suraj.pdf: 1322399 bytes, checksum: 5bbe62233246b6f8243c424518cfa684 (MD5) license.txt: 4064 bytes, checksum: c594c3de8066034506bc0fcc77299238 (MD5)"]},{"key":"dc:title","label":"Title","values":["Insider threat simulation and performance analysis of insider detection algorithms with role based models"]}]}],"canonical_facts":{"dc:contributor":["Nicol, David M."],"dc:creator":["Nellikar, Suraj"],"dc:date":["2010-05-19T18:39:53Z","2010-5"],"dc:description":["Insider threat problems are widespread in industry today. They have resulted in huge losses to organizations. The security reports by leading organizations point out the fact that there have been many more insider attacks in recent years than any other form of attack. Detection of these insider threats is a top priority. One problem facing the detection mechanisms is that the real data for modeling is not easily available. This thesis describes a simulator which can simulate the insiders and generate access information in the form of logs. Currently there are many methods which use data mining algorithms to detect insider attacks. Role based detection is a well known mechanism to accurately distinguish insider behavior from the normal behavior. The thesis focuses on the advantages of using role based mechanisms for insider threat detection. Five algorithms have been chosen and performance analysis of these under various scenarios is carried out. The thesis discusses these results in detail. The simulator is built on the Scalable Simulation Framework (SSF). It is an extension of the Boeing simulator, JANUS. The simulator uses behavior files to model an insider/normal user and generates the access information using Markov chains.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2010-04-27T21:08:44Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 2 Nellikar_Suraj.doc: 1567744 bytes, checksum: 4a130af31f941d4b6ba383daf28cbf9a (MD5) Nellikar_Suraj.pdf: 1322399 bytes, checksum: 5bbe62233246b6f8243c424518cfa684 (MD5)","Made available in DSpace on 2010-05-19T18:39:53Z (GMT). No. of bitstreams: 3 Nellikar_Suraj.doc: 1567744 bytes, checksum: 4a130af31f941d4b6ba383daf28cbf9a (MD5) Nellikar_Suraj.pdf: 1322399 bytes, checksum: 5bbe62233246b6f8243c424518cfa684 (MD5) license.txt: 4064 bytes, checksum: c594c3de8066034506bc0fcc77299238 (MD5)"],"dc:identifier":["http://hdl.handle.net/2142/16177"],"dc:language":["en"],"dc:rights":["Copyright 2010 Suraj Nellikar"],"dc:subject":["Insider threat","Insider detection algorithms","Role-based access control"],"dc:title":["Insider threat simulation and performance analysis of insider detection algorithms with role based models"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:08Z"}