Software Engineering Institute | Carnegie Mellon University
Software Engineering Institute | Carnegie Mellon University

Digital Library

Javascript is currently disabled for your browser. For an optimal search experience, please enable javascript.

Advanced Search

Basic Search

Content Type

Topics

Publication Date

Technical Report

Comparing Insider IT Sabotage and Espionage: A Model-Based Analysis

  • Abstract

    This report examines the psychological, technical, organizational, and contextual factors thought to contribute to at least two forms of insider trust betrayal: insider sabotage against critical information technology (IT) systems, and espionage. Security professionals and policy leaders currently view espionage and insider threat as serious problems but often as separate issues that should be each addressed by a different configuration of security countermeasures. In this study, researchers investigated similarities and differences between insider IT sabotage and espionage cases to isolate the major factors or conditions leading to both categories of trust betrayal. The team developed a descriptive model using the system dynamics methodology that represents the high-level commonalities between the two domains based on models of the individual domains. The effort found definite parallels between the two categories of trust betrayal. Factors observed in both saboteurs and spies include " the contribution of personal predispositions and stressful events to the risk of an insider committing malicious acts " the exhibition of behaviors and technical actions of concern by the insider preceding or during an attack " the failure of their organizations to detect or respond to rule violations " the insufficiency of the organization's physical and electronic access controls. Based on the study's findings and analysis, recommendations and policy implications are also presented.

  • Download

Cite This Report

SEI

Band, Steven; Cappelli, Dawn; Fischer, Lynn; Moore, Andrew; Shaw, Eric; & Trzeciak, Randall. Comparing Insider IT Sabotage and Espionage: A Model-Based Analysis. CMU/SEI-2006-TR-026. Software Engineering Institute, Carnegie Mellon University. 2006. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=8163

IEEE

Band. Steven, Cappelli. Dawn, Fischer. Lynn, Moore. Andrew, Shaw. Eric, and Trzeciak. Randall, "Comparing Insider IT Sabotage and Espionage: A Model-Based Analysis," Software Engineering Institute, Carnegie Mellon University, Pittsburgh, Pennsylvania, Technical Report CMU/SEI-2006-TR-026, 2006. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=8163

APA

Band, Steven., Cappelli, Dawn., Fischer, Lynn., Moore, Andrew., Shaw, Eric., & Trzeciak, Randall. (2006). Comparing Insider IT Sabotage and Espionage: A Model-Based Analysis (CMU/SEI-2006-TR-026). Retrieved September 29, 2016, from the Software Engineering Institute, Carnegie Mellon University website: http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=8163

CHI

Steven Band, Dawn Cappelli, Lynn Fischer, Andrew Moore, Eric Shaw, & Randall Trzeciak. Comparing Insider IT Sabotage and Espionage: A Model-Based Analysis (CMU/SEI-2006-TR-026). Pittsburgh, PA: Software Engineering Institute, Carnegie Mellon University, 2006. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=8163

MLA

Band, Steven., Cappelli, Dawn., Fischer, Lynn., Moore, Andrew., Shaw, Eric., & Trzeciak, Randall. 2006. Comparing Insider IT Sabotage and Espionage: A Model-Based Analysis (Technical Report CMU/SEI-2006-TR-026). Pittsburgh: Software Engineering Institute, Carnegie Mellon University. http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=8163

BibTex

@techreport{BandComparingInsider2006,
title={Comparing Insider IT Sabotage and Espionage: A Model-Based Analysis},
author={Steven Band and Dawn Cappelli and Lynn Fischer and Andrew Moore and Eric Shaw and Randall Trzeciak},
year={2006},
number={CMU/SEI-2006-TR-026},
institution={Software Engineering Institute, Carnegie Mellon University},
address={Pittsburgh, PA},
url={http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=8163} }