A special programs team at Hanscom Air Force Base in Massachusetts is working to rapidly research and identify technologies to help the Air Force and the Defense Department combat insider threats.
The small unit of engineers from Hanscom’s Command, Control, Communications, Intelligence and Networks Directorate is part of the Special Programs Division, which established the Materiel Solutions Analysis (MSA) section in January 2014. MSA’s mission is to identify and test government and commercial technologies to meet the needs of the Air Force classified networks.
As MSA tested technologies, the team discovered that many companies were claiming that their one solution could solve the insider threat problem for the entire Air Force, which is just not possible, said Lt Col Richard Howard, Materiel Solutions Analysis chief. “This is a complex problem and … there is no one technology that is going to solve the problem. It is going to be layers and not just technology.”
Malicious insider threats typically come from a current or former employee, contractor or business partner who has or had authorized access to an organization’s network, systems or data and intentionally exceeded or misused that access in a manner that negatively affected the confidentiality, integrity or availability of the organization’s information or information systems.
To better understand and depict the intricacies of the insider threat problem, MSA engineers devised a model known as the Insider Threat Universe (ITU), which conveys how certain technologies protect parts of the Air Force’s secure networks. Confidentiality, integrity and availability make up the basis of the ITU with information serving as the core. Procedures, policies and monitoring are other items that directly impact the protection of information. Specific areas such as data-at-rest encryption and role-based access controls represent the technology layers also used to protect information.
By using ITU, the MSA team can give senior commanders a better understanding of where a certain technology might fit in the protection of an information asset and, as a result, avoid buying technologies that might overlap functions, Howard noted.
Security administrators also need to make sure the proper security controls are in place to lock down information. The National Institute of Standards and Technology’s Special Publication 800-53 Revision 4 describes security controls for the insider threat. Other organizations, such as the SANS Institute, do so as well. There are about 700 security controls for insider threats.
Government engineers and military engineers are applying the controls to a study designed by the MIT Lincoln Laboratory. They are applying vulnerability and penetration testing tools to probe for security weaknesses and locking down controls to see what would affect the productivity of a general user, said Paul Krueger, MSA chief engineer. “They are measuring controls with mathematical measurements, not just anecdotal evidence,” Kruger said.
Technology is advancing quickly and organizations want to leverage new capabilities, but they can’t rely just on technology, said Keith Johnson, technical director for Analysis and Mission Solutions at Lockheed Martin. Organizations must be able to model human behavior and how people interact across an enterprise. Cyber is one component of the equation, but activities beyond cyber need to be monitored, too.
Lockheed Martin’s Wisdom Insider Threat Identification (ITI) helps organizations zero in on individuals who could be prone to steal or leak information or disrupt services that could cause physical harm and damage. ITI evaluates employee attributes, behaviors and actions based on data fusion from large disparate enterprise systems — even performance reviews and human resource information — and counterintelligence from analyst-defined models. Analysts can drill down for further investigation, as well as discover new information through automated link analysis.
Hanscom’s MSA team is also working with the Air Force Research Laboratory on behavior analysis, Howard said. There are two areas: behavioral informatics, which looks at the files people are attempting to open and systems they are looking at, and behavioral haptics that would look for abnormal behavior when a person is typing on a keyboard, for instance.




