The dissertation presents the results of research aimed at solving the urgent scientific problem of creating a model of an intelligent system for detecting insider threats in cloud services based on a modified Bayesian network.
The proposed solution is of significant importance for the development of information technologies, as it enables the consideration of behavioral, technical, and organizational indicators, as well as scenarios of fraudulent actions by managerial personnel. The obtained results have been implemented in the form of a prototype decision support system, which makes it possible to integrate the model into information security tools for cloud systems.
The rapid implementation of cloud services (CS) in the main sectors of the economy and public administration – finance, healthcare, logistics, energy, education, etc. – has created the need for effective management of information security (IS) risks, particularly those associated with insider threats. Although cloud computing (CC) provides high flexibility, scalability, and speed of data processing, it simultaneously complicates the control of user behavior and contributes to an increased likelihood of security breaches by internal subjects of access. Insider threats are now recognized as among the most dangerous and least controllable forms of attacks on the information security of cloud environments.The relevance of the research is determined by the need to create improved probabilistic models and methods for detecting insider threats in cloud environments that combine analytical rigour, adaptability to user behaviour scenarios, and the possibility of implementation in practical cyber defence systems.
To achieve the research goal, a modified Bayesian network model for detecting insider threats in cloud services was developed. It differs in its structure, which includes nodes for assessing fraudulent actions of managerial personnel, and in its ability to take into account digital traces generated in the process of interaction with the cloud infrastructure. A procedure for constructing optimal sequential Bayesian rules has been studied and implemented, enabling the assessment of the probability of an information security violation even before an incident occurs, taking into account causal and nonlinear dependencies between risks. The use of technical, behavioral, and organizational indicators in the tasks of forecasting insider activity has been substantiated. The results have also been implemented in software form as a prototype decision support system for information security specialists, which provides interactive interaction with an analyst, visualization of results, and support for making informed decisions regarding internal (insider) threats.
For the first time, a modified Bayesian network model for detecting insider threats in cloud services of information systems has been developed. Unlike existing solutions, the model includes specialized nodes for taking into account the actions of individuals in managerial positions and models the risks of fraudulent behavior by such personnel. The model takes into account digital traces generated during user interaction with cloud applications, which makes it possible to assess the probability of internal threats before an actual violation occurs. The structure of the developed model includes a description of prior and posterior probabilities for key technical, behavioral, and organizational indicators, providing deeper causal modeling of threat situations under conditions of incomplete information.
The method for detecting unauthorized access to cloud services has been improved by introducing an adaptive Bayesian network with functionality for forecasting insider threats. The distinctive feature of this approach is that it takes into account not only current threat indicators but also their interdependencies over time, enabling threats to be detected at early stages and violations to be prevented in a timely manner. A refined procedure has been proposed for constructing optimal sequential Bayesian rules, which allows the adaptation of threshold values for risk assessment depending on the context of actions. This approach is based on minimizing posterior risk and enables well-grounded security decisions to be made under conditions of multi-criteria uncertainty.