The Danger Within: Insider Threat Modeling Using Business Process Models
Jan von der Assen, Jasmin Hochuli, Thomas Gr\"ubl, Burkhard Stiller

TL;DR
This paper introduces a novel method for modeling insider threats using business process models, specifically BPMN, and demonstrates its practical effectiveness through real-world case studies and experiments.
Contribution
It develops a new insider threat knowledge base and a threat modeling application leveraging BPMN, addressing the gap in modeling non-technical assets.
Findings
BPMN diagrams can automatically identify insider threats.
The approach is effective in real-world organizational and voting processes.
The method enhances insider threat detection without requiring diagram annotations.
Abstract
Threat modeling has been successfully applied to model technical threats within information systems. However, a lack of methods focusing on non-technical assets and their representation can be observed in theory and practice. Following the voices of industry practitioners, this paper explored how to model insider threats based on business process models. Hence, this study developed a novel insider threat knowledge base and a threat modeling application that leverages Business Process Modeling and Notation (BPMN). Finally, to understand how well the theoretic knowledge and its prototype translate into practice, the study conducted a real-world case study of an IT provider's business process and an experimental deployment for a real voting process. The results indicate that even without annotation, BPMN diagrams can be leveraged to automatically identify insider threats in an organization.
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsBusiness Process Modeling and Analysis · Information and Cyber Security · Big Data and Business Intelligence
