RUS  ENG
Full version
JOURNALS // Sistemy i Sredstva Informatiki [Systems and Means of Informatics] // Archive

Sistemy i Sredstva Inform., 2017 Volume 27, Issue 2, Pages 41–47 (Mi ssi514)

This article is cited in 2 papers

Possibility of insider detection by statistical techniques

E. A. Martyanov

M. V. Lomonosov Moscow State University, Faculty of Computational Mathematics and Cybernetics, GSP-1, Leninskie Gory, Moscow 119991, Russian Federation

Abstract: The paper considers the task of insider detection in a group of analytics, who work with a data warehouse, presented as a raw table with a huge amount of attributes. The difference between a legal analyst and an insider is that an insider collects redundant data during his regular work to perform a threat. Therefore, in order to detect an insider, it is necessary to detect the fact of continuously collecting redundant data during a work cycle with a data warehouse. A mathematical model is defined. The author suggests to use statistical techniques with probability of false alarms equal to zero. The author found conditions, under which the power of statistical criteria reaches the value of 1 after a finite number of steps, which means that an insider can be detected definitely.

Keywords: insider threat; anomaly detection; bans of probability measures; statistical criteria; power of criteria.

Received: 15.03.2017

DOI: 10.14357/08696527170204



Bibliographic databases:


© Steklov Math. Inst. of RAS, 2026