Research on Multi-Factor Driven Insider Threat Risk Measurement Method of Information System

25 Pages Posted: 23 Dec 2024

See all articles by Zifei ma

Zifei ma

Yunnan Agricultural University

wengang Li

Yunnan Agricultural University

Tong Li

Yunnan Agricultural University

Juan Yang

affiliation not provided to SSRN

Jing Li

Yunnan Agricultural University

Aoting Wan

Yunnan Agricultural University

Qinghua Li

Yunnan Agricultural University

Liming Yang

Yunnan Agricultural University

Multiple version iconThere are 2 versions of this paper

Abstract

Internal threats pose significant challenges to cybersecurity. This article proposes a novel method that calculates internal threat risk before a security incident occurs, unlike most studies that focus on detection after incidents. Firstly, the research identifies personal factors, organizational management, and security technology as key drivers of internal personnel's threatening behavior. Based on these dimensions, an internal threat risk measurement index system for information systems is constructed, comprising a target layer, class layer (three types of risks), subclass layer (14 subclasses), factor layer (61 risk factors), and instance layer (112 instances). This indicator system can comprehensively describe the characteristics of internal threat risks. Secondly, the questionnaire designed in this paper assigns a value to the risk instance, and then proposes an internal threat risk measurement method based on Information Entropy, which can effectively and reasonably calculate the potential internal threat risk (including the risk level of individual, organization management, security technology and the overall). Finally, by comparing with the existing research, the advantages of comprehensiveness, extensibility and operability of this study are highlighted. This study can help decision-makers to discover the causes of internal threat risks, and provide important reference and basis for risk prevention and decision making.

Keywords: insider threats, insider threat risk measurement, insider threat indicator system, insider threat risk management, technical security risks

Suggested Citation

ma, Zifei and Li, wengang and Li, Tong and Yang, Juan and Li, Jing and Wan, Aoting and Li, Qinghua and Yang, Liming, Research on Multi-Factor Driven Insider Threat Risk Measurement Method of Information System. Available at SSRN: https://ssrn.com/abstract=5069329 or http://dx.doi.org/10.2139/ssrn.5069329

Zifei Ma

Yunnan Agricultural University ( email )

Kunming
China

Wengang Li

Yunnan Agricultural University ( email )

Kunming
China

Tong Li (Contact Author)

Yunnan Agricultural University ( email )

Kunming
China

Juan Yang

affiliation not provided to SSRN ( email )

No Address Available

Jing Li

Yunnan Agricultural University ( email )

Kunming
China

Aoting Wan

Yunnan Agricultural University ( email )

Kunming
China

Qinghua Li

Yunnan Agricultural University ( email )

Kunming
China

Liming Yang

Yunnan Agricultural University ( email )

Kunming
China

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Downloads
18
Abstract Views
101
PlumX Metrics