Playbook Generation for Process Anomalies in Insider Threat Scenarios
Abstract
: Insider threats represent a big challenge for organizations because insiders have legitimate access and knowledge of organizational processes. Effective defense requires both accurate detection of anomalous behavior and timely response actions. This paper proposes a unified approach that classifies log attributes by their importance for insider threat detection using process mining and an anomaly score to identify process deviations. To address the lack of automated responses, we propose to generate Incident Response (IR) playbooks for business processes using Named Entity Recognition (NER) on insider threat scenarios, combined with Part-of-Speech (POS) tagging and the RE&CT framework, a knowledge base of attack techniques and tactics inspired by MITRE ATT&CK that allows for categorizing IR techniques and actions, to map entities to response actions. The proposed approach is evaluated using coverage, redundancy, usefulness, and efficiency metrics, demonstrating its ability to produce comprehensive and compact response playbooks.