000 04407nam a22004215i 4500
999 _c386841
_d386841
001 386841
003 ES-MaUEC
005 20230124192638.0
006 a||||fo|||| 00| 0
007 cr nn 008mamaa
008 220601s2012 sz | s |||| 0|eng d
020 _a9783031018909
024 7 _a10.1007/978-3-031-01890-9
_2doi
040 _aES-MaUEC
_bspa
_cES-MaUEC
_dES-MaUEC
050 4 _aQA76.9.A25
_b2012 EB
100 1 _aBertino, Elisa
_eautor
_4aut
_4http://id.loc.gov/vocabulary/relators/aut
_9686190
245 1 0 _aData Protection from Insider Threats
_cby Elisa Bertino
250 _a1st edition 2012
264 1 _aCham
_bSpringer International Publishing
_c2012
300 _a1 recurso en línea (XIII, 77 páginas)
336 _atexto
_btxt
_2rdacontent
337 _aelectrónico
_bc
_2rdamedia
338 _arecurso electrónico
_bcr
_2rdacarrier
347 _aarchivo de texto
_bPDF
490 0 _aSynthesis Lectures on Data Management
_x2153-5426
505 0 _aIntroduction -- Authentication -- Access Control -- Anomaly Detection -- Security Information and Event Management and Auditing -- Separation of Duty -- Case Study: Oracle Database Vault -- Conclusion.
520 _aAs data represent a key asset for today's organizations, the problem of how to protect this data from theft and misuse is at the forefront of these organizations' minds. Even though today several data security techniques are available to protect data and computing infrastructures, many such techniques -- such as firewalls and network security tools -- are unable to protect data from attacks posed by those working on an organization's "inside." These "insiders" usually have authorized access to relevant information systems, making it extremely challenging to block the misuse of information while still allowing them to do their jobs. This book discusses several techniques that can provide effective protection against attacks posed by people working on the inside of an organization. Chapter One introduces the notion of insider threat and reports some data about data breaches due to insider threats. Chapter Two covers authentication and access control techniques, and Chapter Three shows how these general security techniques can be extended and used in the context of protection from insider threats. Chapter Four addresses anomaly detection techniques that are used to determine anomalies in data accesses by insiders. These anomalies are often indicative of potential insider data attacks and therefore play an important role in protection from these attacks. Security information and event management (SIEM) tools and fine-grained auditing are discussed in Chapter Five. These tools aim at collecting, analyzing, and correlating -- in real-time -- any information and event that may be relevant for the security of an organization. As such, they can be a key element in finding a solution to such undesirable insider threats. Chapter Six goes on to provide a survey of techniques for separation-of-duty (SoD). SoD is an important principle that, when implemented in systems and tools, can strengthen data protection from malicious insiders. However, to date, very few approaches have been proposed for implementing SoD in systems. In Chapter Seven, a short survey of a commercial product is presented, which provides different techniques for protection from malicious users with system privileges -- such as a DBA in database management systems. Finally, in Chapter Eight, the book concludes with a few remarks and additional research directions. Table of Contents: Introduction / Authentication / Access Control / Anomaly Detection / Security Information and Event Management and Auditing / Separation of Duty / Case Study: Oracle Database Vault / Conclusion.
988 _aSynthesis Collection of Technology_2012
650 7 _2embne
_9158200
_aSeguridad informática
650 0 _9686189
_aORACLE (Programa de ordenador)
650 7 _9147793
_aProtección de datos
_2embne
776 0 8 _iPrinted edition:
_z9783031007620
776 0 8 _iPrinted edition:
_z9783031030185
856 4 0 _uhttps://go.openathens.net/redirector/universidadeuropea.es?url=https://doi.org/10.1007/978-3-031-01890-9
_zAcceso a este recurso digital (usuarios Universidad Europea de Madrid)
942 _2lcc
_cLE
998 _b01/2023
_dz
_esc
_zSI