Linking data and process perspectives for conformance analysis

Research output: Contribution to journalArticleAcademicpeer-review

15 Citations (Scopus)

Abstract

The detection of data breaches has become a major challenge for most organizations. The problem lies in the fact that organizations often lack proper mechanisms to control and monitor users' activities and their data usage. Although several auditing approaches have been proposed to assess the compliance of actual executed behavior, existing approaches focus on either checking data accesses against security policies (data perspective) or checking user activities against the activities needed to conduct business processes (process perspective). Analyzing user behavior from these perspectives independently may not be sufficient to expose security incidents. In particular, security incidents may remain undetected or diagnosed incorrectly. This paper proposes a novel auditing approach that reconciles the data and process perspectives, thus enabling the identification of a large range of deviations. In particular, we analyze and classify deviations with respect to the intended purpose of data and the context in which data are used, and provide a novel algorithm to identify non-conforming user behavior. The approach has been implemented in the open source framework ProM and was evaluated through both controlled experiments and a case study using real-life event data. The results show that the approach is able to accurately identify deviations in both data usage and control-flow, while providing the purpose and context of the identified deviations.
Original languageEnglish
Pages (from-to)172-193
Number of pages22
JournalComputers and Security
Volume73
Early online date7 Nov 2017
DOIs
Publication statusPublished - Mar 2018

Keywords

  • Alignments
  • Auditing
  • Compliance checking
  • Conformance checking
  • Multi-perspective analysis
  • Process mining

Fingerprint Dive into the research topics of 'Linking data and process perspectives for conformance analysis'. Together they form a unique fingerprint.

  • Cite this