CERT
 
Publications CatalogHistorical Documents CERT Contact Information CERT Statistics Meet CERT Employment Opportunities
 

Insider Threat Research

Background and Work

Our insider threat research focuses on both technical and behavioral aspects of actual compromises. We produce models, reports, training, and tools to raise awareness of the risks of insider threat and to help identify the factors influencing an insider's decision to act, the indicators and precursors of malicious acts, and the countermeasures that will improve the survivability and resiliency of the organization.

Our work consists of the following:

  • Case Analysis and Best Practices
  • Modeling and Simulation
  • Training Materials
  • Virtual Interactive Simulation for Insider Threat Risk Management
  • Insider Threats in the Software Development Lifecycle
  • Annual eCrime Watch Survey
  • Espionage Research
Learn more about our work.

Case Analysis and Best Practices

In 2002, the Insider Threat Study team, comprised of U.S. Secret Service (USSS) behavioral psychologists and CERT information security experts, collected approximately 150 actual insider threat cases that occurred in US critical infrastructure sectors between 1996 and 2002, and examined them from both a technical and a behavioral perspective. A series of four reports has been published as a result of this work: a report of cases in the banking and finance sector, the IT sector, the government sector, and all critical infrastructure sectors.

Learn more about our case studies and best practices work.

Common Sense Guide to Prevention and Detection of Insider Threats (pdf). A CyLab funded guide to best practices for the prevention and detection of insider threat.

Modeling and Simulation

CERT's insider threat modeling, referred to as MERIT (Management and Education of the Risk of Insider Threat), uses empirical data collected by CERT to convey the "big picture" of the insider threat problem. The MERIT project, funded by Carnegie Mellon's CyLab, employs system dyanmics modeling and simulation to convey the complexity of the problem. Learn more about modeling and simulation.

 

CERT also conducts espionage research, those efforts began with the DoD Personnel Security Research Center (PERSEREC). PERSEREC funded a study to investigate similarities and differences between insider IT sabotage and espionage cases to assess the feasibility of the development a single analytical framework based on system dynamics modeling.

E-Crime Watch Survey

The Insider Threat Team has also teamed with the U.S. Secret Service and CSO magazine to conduct, analyze, and publish findings from an annual E-Crime Watch survey from research that was conducted to attempt to identify electronic crime fighting trends and techniques, including best practices and emerging trends.


What's New

Contact Us

We welcome your feedback. Contact us at the following email address if you have questions or comments, if you are interested in collaborating with us, or if you would like more information:




Copyright 2008 Carnegie Mellon University.

Last updated June 11, 2008