<p>Insider threats continue to be a vexed and complicated risk in secure software development (SSD) organizations due to their origin in combination of malicious intent, negligence, credential abuse, and process vulnerability throughout the software development lifecycle. Artificial intelligence (AI)-inspired, agentic security strategies are increasingly suggested to enhance prevention and detection, but organizations have not yet a clear, decision-supportive approach to prioritize agentic mitigation practices in times of uncertainty. This paper aims to suggest and rank an agentic model of insider threats mitigation to secure software development companies based on the Fuzzy Analytic Hierarchy Process (Fuzzy AHP). Its main objectives include (i) organizing insider-threat mitigation into multi-level decision model, (ii) calculating priority weights of AI-directed agentic practices, and (iii) assisting actionable adoption choices of various insider-threat types. A systematic mapping study (SMS) was first carried out to investigate the state-of-the-art of insider threats in software development organization. The second phase involved performing an empirical survey among cybersecurity professionals to confirm the findings of SMS and determine the types of insider threats and AI-driven agentic practices in preventing and mitigating insider threats. Comparison of the results of empirical survey and MLR was then done using ANOVA test. To find weights and ranking of insider threats and AI-Driven agentic practices, the last stage was a fuzzy analytical hierarchy process (FAHP). Standard FAHP validation steps were verified to give consistency and a sensitivity analysis was performed to check the consistency of the rankings with small perturbations of criterion weights. A hierarchical decision model was created, the overall aim of which was insider threats reduction in secure software development organizations, which were broken down into nine types of insider threats (e.g., malicious insiders, negligent insiders, credential theft, inadvertent misuse of access, privilege abuse, social engineering, software piracy/code theft, insider data exfiltration, and abuse of development tools). 91 AI-based agentic practices were discovered to prevent and detect these insider threats. The most highlighted insider threat to software development organizations was considered to be using FAHP credential theft with final weight 0.1262. In the same way, the agentic practice that was mentioned as the most cited with final weight 0.020580 and global rank-1 was the machine learning driven anomaly detection. The suggested agentic framework based on AI, which is operationalized using Fuzzy AHP, provides a structured and understandable procedure to rank the practices of insider-threat mitigation in secure software development organizations. The framework assists in supporting more justifiable security investment choices by considering uncertainty when expert judgments are involved and assisting in the realignment of agentic controls to the threat-specific needs within the entire development environment.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Exploring an AI-driven agentic framework for insider threat detection in secure software development organizations: A survey-based approach

  • Muhammad Shafiq,
  • Mujtaba Awan,
  • Hathal Salamah Alwageed,
  • Umar,
  • Mohammad Mehedi Hassan,
  • Rafiq Ahmad Khan,
  • M. Anwar Hossain

摘要

Insider threats continue to be a vexed and complicated risk in secure software development (SSD) organizations due to their origin in combination of malicious intent, negligence, credential abuse, and process vulnerability throughout the software development lifecycle. Artificial intelligence (AI)-inspired, agentic security strategies are increasingly suggested to enhance prevention and detection, but organizations have not yet a clear, decision-supportive approach to prioritize agentic mitigation practices in times of uncertainty. This paper aims to suggest and rank an agentic model of insider threats mitigation to secure software development companies based on the Fuzzy Analytic Hierarchy Process (Fuzzy AHP). Its main objectives include (i) organizing insider-threat mitigation into multi-level decision model, (ii) calculating priority weights of AI-directed agentic practices, and (iii) assisting actionable adoption choices of various insider-threat types. A systematic mapping study (SMS) was first carried out to investigate the state-of-the-art of insider threats in software development organization. The second phase involved performing an empirical survey among cybersecurity professionals to confirm the findings of SMS and determine the types of insider threats and AI-driven agentic practices in preventing and mitigating insider threats. Comparison of the results of empirical survey and MLR was then done using ANOVA test. To find weights and ranking of insider threats and AI-Driven agentic practices, the last stage was a fuzzy analytical hierarchy process (FAHP). Standard FAHP validation steps were verified to give consistency and a sensitivity analysis was performed to check the consistency of the rankings with small perturbations of criterion weights. A hierarchical decision model was created, the overall aim of which was insider threats reduction in secure software development organizations, which were broken down into nine types of insider threats (e.g., malicious insiders, negligent insiders, credential theft, inadvertent misuse of access, privilege abuse, social engineering, software piracy/code theft, insider data exfiltration, and abuse of development tools). 91 AI-based agentic practices were discovered to prevent and detect these insider threats. The most highlighted insider threat to software development organizations was considered to be using FAHP credential theft with final weight 0.1262. In the same way, the agentic practice that was mentioned as the most cited with final weight 0.020580 and global rank-1 was the machine learning driven anomaly detection. The suggested agentic framework based on AI, which is operationalized using Fuzzy AHP, provides a structured and understandable procedure to rank the practices of insider-threat mitigation in secure software development organizations. The framework assists in supporting more justifiable security investment choices by considering uncertainty when expert judgments are involved and assisting in the realignment of agentic controls to the threat-specific needs within the entire development environment.