2011
DOI: 10.1002/sec.362
|View full text |Cite
|
Sign up to set email alerts
|

Enhancing directory virtualization to detect insider activity

Abstract: One of the critical yet lingering issues in computer security is insider threat, and it often takes advantage of some security services based on directory services such as authentication and access control. Detecting these threats is quite challenging because malicious users with the technical ability to leverage these services often have sufficient knowledge and expertise to conceal unauthorized activity. In this article, we present an approach using directory virtualization to monitor various systems across … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2015
2015
2021
2021

Publication Types

Select...
3
2

Relationship

0
5

Authors

Journals

citations
Cited by 5 publications
(1 citation statement)
references
References 22 publications
0
1
0
Order By: Relevance
“…Their proposed approach gathers cross‐domain identity information, removes unnecessary accounts, and filters account data and access rights in order to prevent insiders from obtaining unauthorized information. Claycomb et al , proposed a framework for directory virtualization in order to detect insider attacks against directory services.…”
Section: Background and Related Workmentioning
confidence: 99%
“…Their proposed approach gathers cross‐domain identity information, removes unnecessary accounts, and filters account data and access rights in order to prevent insiders from obtaining unauthorized information. Claycomb et al , proposed a framework for directory virtualization in order to detect insider attacks against directory services.…”
Section: Background and Related Workmentioning
confidence: 99%