{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,28]],"date-time":"2026-04-28T15:38:39Z","timestamp":1777390719528,"version":"3.51.4"},"reference-count":59,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2021,3,30]],"date-time":"2021-03-30T00:00:00Z","timestamp":1617062400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Russian Ministry of Science (information security)","award":["5\/2020"],"award-info":[{"award-number":["5\/2020"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JSAN"],"abstract":"<jats:p>One of the reasons for the implementation of information security threats in organizations is the insider activity of its employees. There is a big challenge to detect stego-insiders-employees who create stego-channels to secretly receive malicious information and transfer confidential information across the organization\u2019s perimeter. Especially presently, with great popularity of wireless sensor networks (WSNs) and Internet of Things (IoT) devices, there is a big variety of information that could be gathered and processed by stego-insiders. Consequently, the problem arises of identifying such intruders and their transmission channels. The paper proposes an approach to solving this problem. The paper provides a review of the related works in terms of insider models and methods of their identification, including techniques for handling insider attacks in WSN, as well methods of embedding and detection of stego-embeddings. This allows singling out the basic features of stego-insiders, which could be determined by their behavior in the network. In the interests of storing these attributes of user behavior, as well as storing such attributes from large-scale WSN, a hybrid NoSQL database is created based on graph and document-oriented approaches. The algorithms for determining each of the features using the NoSQL database are specified. The general scheme of stego-insider detection is also provided. To confirm the efficiency of the approach, an experiment was carried out on a real network. During the experiment, a database of user behavior was collected. Then, user behavior features were retrieved from the database using special SQL queries. The analysis of the results of SQL queries is carried out, and their applicability for determining the attribute is justified. Weak points of the approach and ways to improve them are indicated.<\/jats:p>","DOI":"10.3390\/jsan10020025","type":"journal-article","created":{"date-parts":[[2021,3,31]],"date-time":"2021-03-31T00:13:10Z","timestamp":1617149590000},"page":"25","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["An Approach for Stego-Insider Detection Based on a Hybrid NoSQL Database"],"prefix":"10.3390","volume":"10","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6859-7120","authenticated-orcid":false,"given":"Igor","family":"Kotenko","sequence":"first","affiliation":[{"name":"St. Petersburg Federal Research Center of the Russian Academy of Sciences, 199178 St. Petersburg, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9076-6055","authenticated-orcid":false,"given":"Andrey","family":"Krasov","sequence":"additional","affiliation":[{"name":"Department of Secured Communication Systems, The Bonch-Bruevich State University of Telecommunications, 199178 St. Petersburg, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6988-9261","authenticated-orcid":false,"given":"Igor","family":"Ushakov","sequence":"additional","affiliation":[{"name":"Department of Secured Communication Systems, The Bonch-Bruevich State University of Telecommunications, 199178 St. Petersburg, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9412-5693","authenticated-orcid":false,"given":"Konstantin","family":"Izrailov","sequence":"additional","affiliation":[{"name":"St. Petersburg Federal Research Center of the Russian Academy of Sciences, 199178 St. Petersburg, Russia"},{"name":"Department of Secured Communication Systems, The Bonch-Bruevich State University of Telecommunications, 199178 St. Petersburg, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2021,3,30]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Mescheryakov, S., Shchemelinin, D., Izrailov, K., and Pokussov, V. (2020). Digital Cloud Environment: Present Challenges and Future Forecast. Future Internet, 12.","DOI":"10.3390\/fi12050082"},{"key":"ref_2","unstructured":"Schneier, B. (2000). Secrets & Lies: Digital Security in a Networked World, John Wiley & Sons, Inc.. [1st ed.]."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Simmons, G.J. (1983). The Prisoners\u2019 Problem and the Subliminal Channel. Advances in Cryptology: Proceedings of CRYPTO \u201983, Springer.","DOI":"10.1007\/978-1-4684-4730-9_5"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"25167","DOI":"10.1109\/ACCESS.2018.2817560","article-title":"A Systematic Review of the Availability and Efficacy of Countermeasures to Internal Threats in Healthcare Critical Infrastructure","volume":"6","author":"Hammoudeh","year":"2018","journal-title":"IEEE Access"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"2643","DOI":"10.1007\/s11227-019-03028-9","article-title":"Threats on the horizon: Understanding security threats in the era of cyber-physical systems","volume":"76","author":"Hammoudeh","year":"2020","journal-title":"J. Supercomput."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Kotenko, I., Krasov, A., Ushakov, I., and Izrailov, K. (2020, January 28). Detection of Stego-Insiders in Corporate Networks Based on a Hybrid NoSQL Database Model. Proceedings of the 4th International Conference on Future Networks and Distributed Systems (ICFNDS), St. Petersburg, Russia.","DOI":"10.1145\/3440749.3442612"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"737","DOI":"10.1109\/TLA.2017.7896402","article-title":"Internet of Things Data Storage Infrastructure in the Cloud Using NoSQL Databases","volume":"15","author":"Vanelli","year":"2017","journal-title":"IEEE Lat. Am. Trans."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"67818","DOI":"10.1109\/ACCESS.2019.2926206","article-title":"Multilevel Object Tracking in Wireless Multimedia Sensor Networks for Surveillance Applications Using Graph-Based Big Data","volume":"7","author":"Yazici","year":"2019","journal-title":"IEEE Access"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Roy, P., and Mazumdar, C. (2018, January 12\u201313). Modeling of Insider Threat using Enterprise Automaton. Proceedings of the 2018 Fifth International Conference on Emerging Applications of Information Technology (EAIT), West Bengal, India.","DOI":"10.1109\/EAIT.2018.8470428"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Santos, E.E., Santos, E., Korah, J., Thompson, J.E., Murugappan, V., Subramanian, S., and Zhao, Z. (2017, January 25\u201326). Modeling insider threat types in cyber organizations. Proceedings of the 2017 IEEE International Symposium on Technologies for Homeland Security (HST), Greater Boston, MA, USA.","DOI":"10.1109\/THS.2017.7943445"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Igbe, O., and Saadawi, T. (2018, January 8\u201310). Insider Threat Detection using an Artificial Immune system Algorithm. Proceedings of the 2018 9th IEEE Annual Ubiquitous Computing, Electronics Mobile Communication Conference (UEMCON), New York, NY, USA.","DOI":"10.1109\/UEMCON.2018.8796583"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Jat, D.S., Shukla, S., Unal, A., and Mishra, D.K. (2021). Insider Threat Detection Based on Anomalous Behavior of User for Cybersecurity. Data Science and Security, Springer.","DOI":"10.1007\/978-981-15-5309-7"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Almazaydeh, W.I.A., and Sheshadri, H.S. (2018, January 11\u201312). Image Steganography Using a Dynamic Symmetric Key. Proceedings of the 2018 2nd International Conference on Trends in Electronics and Informatics (ICOEI), Tirunelveli, India.","DOI":"10.1109\/ICOEI.2018.8553778"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Avci, D., Tuncer, T., and Avci, E. (2018, January 22\u201325). A new information hiding method for audio signals. Proceedings of the 2018 6th International Symposium on Digital Forensic and Security (ISDFS), Antalya, Turkey.","DOI":"10.1109\/ISDFS.2018.8355361"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Badica, C., Liatsis, P., Kharb, L., and Chahal, D. (2020). Network Steganography Using Extension Headers in IPv6. Information, Communication and Computing Technology, Springer.","DOI":"10.1007\/978-981-15-9671-1"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"291","DOI":"10.1109\/TIFS.2020.3013204","article-title":"A Siamese CNN for Image Steganalysis","volume":"16","author":"You","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Smolarczyk, M., Szczypiorski, K., and Pawluk, J. (2020). Multilayer Detection of Network Steganography. Electronics, 9.","DOI":"10.3390\/electronics9122128"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"165","DOI":"10.1016\/j.istr.2008.10.011","article-title":"On handling insider attacks in wireless sensor networks","volume":"13","author":"Schneider","year":"2008","journal-title":"Inf. Secur. Tech. Rep."},{"key":"ref_19","unstructured":"Krau\u00df, C. (2010). Handling Insider Attacks in Wireless Sensor Networks. [Ph.D. Thesis, Technische Universit\u00e4t Darmstadt]."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"494","DOI":"10.1109\/JSYST.2015.2422736","article-title":"Location-Based Key Management Strong Against Insider Threats in Wireless Sensor Networks","volume":"11","author":"Choi","year":"2017","journal-title":"IEEE Syst. J."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"7234","DOI":"10.1109\/ACCESS.2017.2772294","article-title":"Enhancing Trust Management for Wireless Intrusion Detection via Traffic Sampling in the Era of Big Data","volume":"6","author":"Meng","year":"2018","journal-title":"IEEE Access"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"13893","DOI":"10.1007\/s00500-020-04764-4","article-title":"IADF security: Insider attack detection using fuzzy logic in wireless multimedia sensor networks","volume":"24","author":"Janarthanan","year":"2020","journal-title":"Soft Comput."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"2002038","DOI":"10.1002\/adom.202002038","article-title":"Raman Ink for Steganography","volume":"9","author":"Gu","year":"2021","journal-title":"Adv. Opt. Mater."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Wang, S., Zheng, N., and Xu, M. (2021). A Compression Resistant Steganography Based on Differential Manchester Code. Symmetry, 13.","DOI":"10.3390\/sym13020165"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Liu, F., Zhou, X., Yan, X., Lu, Y., and Wang, S. (2021). Image Steganalysis via Diverse Filters and Squeeze-and-Excitation Convolutional Neural Network. Mathematics, 9.","DOI":"10.3390\/math9020189"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"J\u00e4rpe, E., and Weckst\u00e9n, M. (2021). Velody 2\u2014Resilient High-Capacity MIDI Steganography for Organ and Harpsichord Music. Appl. Sci., 11.","DOI":"10.3390\/app11010039"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Xiang, L., Yang, S., Liu, Y., Li, Q., and Zhu, C. (2020). Novel Linguistic Steganography Based on Character-Level Text Generation. Mathematics, 8.","DOI":"10.3390\/math8091558"},{"key":"ref_28","first-page":"1","article-title":"Audio watermarking system resistant to removal attacks by dereverberation","volume":"15","author":"Korzhik","year":"2018","journal-title":"Int. J. Comput. Sci. Appl."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Kwak, M., and Cho, Y. (2021). A Novel Video Steganography-Based Botnet Communication Model in Telegram SNS Messenger. Symmetry, 13.","DOI":"10.3390\/sym13010084"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Taleby Ahvanooey, M., Li, Q., Hou, J., Rajput, A.R., and Chen, Y. (2019). Modern Text Hiding, Text Steganalysis, and Applications: A Comparative Analysis. Entropy, 21.","DOI":"10.3390\/e21040355"},{"key":"ref_31","first-page":"2746","article-title":"Embedding the hidden information into java byte code based on operands\u2019 interchanging","volume":"13","author":"Krasov","year":"2018","journal-title":"ARPN J. Eng. Appl. Sci."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Sharikov, P., Krasov, A., Gelfand, A., and Kosov, N. (2020). Research of the Possibility of Hidden Embedding of a Digital Watermark Using Practical Methods of Channel Steganography, Springer.","DOI":"10.1007\/978-3-030-32258-8_24"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Mushenko, A., Dzuba, J., Nekrasov, A., and Fidge, C. (2020). A Data Secured Communication System Design Procedure with a Chaotic Carrier and Synergetic Observer. Electronics, 9.","DOI":"10.3390\/electronics9030497"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Liu, J., Tian, H., Chang, C.C., Wang, T., Chen, Y., and Cai, Y. (2018). Steganalysis of Inactive Voice-Over-IP Frames Based on Poker Test. Symmetry, 10.","DOI":"10.3390\/sym10080336"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Sun, C., Tian, H., Chang, C.C., Chen, Y., Cai, Y., Du, Y., Chen, Y.H., and Chen, C.C. (2020). Steganalysis of Adaptive Multi-Rate Speech Based on Extreme Gradient Boosting. Electronics, 9.","DOI":"10.3390\/electronics9030522"},{"key":"ref_36","first-page":"44","article-title":"Side Attacks on Stegosystems Executing Message Encryption Previous to Embedding","volume":"11","author":"Korzhik","year":"2020","journal-title":"J. Inf. Hiding Multimed. Signal Process."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"103149","DOI":"10.1016\/j.csi.2016.10.003","article-title":"Data modeling in the NoSQL world","volume":"67","author":"Atzeni","year":"2020","journal-title":"Comput. Stand. Interfaces"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Venkatraman, S., Fahd, K., and Kaspi, S.R.V. (2016). Versus NoSQL Movement with Big Data Analytics. Int. J. Inf. Technol. Comput. Sci., 59\u201366.","DOI":"10.5815\/ijitcs.2016.12.07"},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3158661","article-title":"A Survey on NoSQL Stores","volume":"51","author":"Davoudian","year":"2018","journal-title":"ACM Comput. Surv."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"1","DOI":"10.33260\/zictjournal.v1i1.8","article-title":"A Comparative Study of NoSQL and Relational Database","volume":"1","author":"Phiri","year":"2017","journal-title":"Zambia ICT J."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Abourezq, M., and Idrissi, A. (2016). Database-as-a-Service for Big Data: An Overview. Int. J. Adv. Comput. Sci. Appl., 7.","DOI":"10.14569\/IJACSA.2016.070124"},{"key":"ref_42","first-page":"4963","article-title":"A Review of NoSQL Databases, Types and Comparison with Relational Database","volume":"6","author":"Priyanka","year":"2016","journal-title":"Int. J. Eng. Sci. Comput."},{"key":"ref_43","first-page":"655","article-title":"An Ontology-based Storage of Security Information","volume":"47","author":"Kotenko","year":"2018","journal-title":"Inf. Technol. Control"},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"945","DOI":"10.3103\/S0146411618080230","article-title":"A Distributed Intrusion Detection System with Protection from an Internal Intruder","volume":"52","author":"Shterenberg","year":"2018","journal-title":"Autom. Control. Comput. Sci."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"5","DOI":"10.15622\/sp.59.1","article-title":"Architecture of the Parallel Big Data Processing System for Security Monitoring of Internet of Things Networks","volume":"4","author":"Kotenko","year":"2018","journal-title":"SPIIRAS Proc."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"5","DOI":"10.15622\/sp.54.1","article-title":"A system for collecting, storing and processing security information and events based on elastic stack tools","volume":"5","author":"Kotenko","year":"2017","journal-title":"SPIIRAS Proc."},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Zheng, Y., Liu, F., Yang, C., Luo, X., and Zhao, K. (2011, January 4\u20136). Identification of Steganography Software Based on Core Instructions Template Matching. Proceedings of the 2011 Third International Conference on Multimedia Information Networking and Security, Shanghai, China.","DOI":"10.1109\/MINES.2011.37"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Zheng, Y., Liu, F., Luo, X., and Yang, C. (2012, January 2\u20134). A Method Based on Feature Matching to Identify Steganography Software. Proceedings of the 2012 Fourth International Conference on Multimedia Information Networking and Security, Nanjing, China.","DOI":"10.1109\/MINES.2012.26"},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Namanya, A.P., Mirza, Q.K.A., Al-Mohannadi, H., Awan, I.U., and Disso, J.F.P. (2016, January 22\u201324). Detection of Malicious Portable Executables Using Evidence Combinational Theory with Fuzzy Hashing. Proceedings of the 2016 IEEE 4th International Conference on Future Internet of Things and Cloud (FiCloud), Vienna, Austria.","DOI":"10.1109\/FiCloud.2016.21"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Naik, N., Jenkins, P., and Savage, N. (2019, January 1\u20133). A Ransomware Detection Method Using Fuzzy Hashing for Mitigating the Risk of Occlusion of Information Systems. Proceedings of the 2019 International Symposium on Systems Engineering (ISSE), Edinburgh, UK.","DOI":"10.1109\/ISSE46696.2019.8984540"},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Balueva, A., Desnitsky, V., and Ushakov, I. (2020). Approach to Detection of Denial-of-Sleep Attacks in Wireless Sensor Networks on the Base of Machine Learning, Springer.","DOI":"10.1007\/978-3-030-32258-8_41"},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"720","DOI":"10.14778\/2977797.2977799","article-title":"Tempo: Robust and Self-Tuning Resource Management in Multi-Tenant Parallel Databases","volume":"9","author":"Tan","year":"2016","journal-title":"Proc. VLDB Endow."},{"key":"ref_53","unstructured":"Parkinson, S., Crampton, A., and Hill, R. (2018). Artificial Intelligence Agents as Mediators of Trustless Security Systems and Distributed Computing Applications. Guide to Vulnerability Analysis for Computer Networks and Systems: An Artificial Intelligence Approach, Springer International Publishing."},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"51871","DOI":"10.1109\/ACCESS.2020.2978458","article-title":"Neural Networks-Aided Insider Attack Detection for the Average Consensus Algorithm","volume":"8","author":"Li","year":"2020","journal-title":"IEEE Access"},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Watada, J., Watanabe, T., Phillips-Wren, G., Howlett, R., and Jain, L. (2012). Enterprise Insider Detection as an Integer Programming Problem. Intelligent Decision Technologies. Smart Innovation, Systems and Technologies, Springer.","DOI":"10.1007\/978-3-642-29920-9"},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"183162","DOI":"10.1109\/ACCESS.2019.2957055","article-title":"Insider Threat Identification Using the Simultaneous Neural Learning of Multi-Source Logs","volume":"7","author":"Liu","year":"2019","journal-title":"IEEE Access"},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"660","DOI":"10.1109\/TCSS.2018.2857473","article-title":"Scenario-Based Insider Threat Detection From Cyber Activities","volume":"5","author":"Chattopadhyay","year":"2018","journal-title":"IEEE Trans. Comput. Soc. Syst."},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"35926","DOI":"10.1109\/ACCESS.2018.2851228","article-title":"A Novel Mechanism for Fast Detection of Transformed Data Leakage","volume":"6","author":"Huang","year":"2018","journal-title":"IEEE Access"},{"key":"ref_59","doi-asserted-by":"crossref","first-page":"11743","DOI":"10.1109\/ACCESS.2019.2959047","article-title":"Malicious Insider Attack Detection in IoTs Using Data Analytics","volume":"8","author":"Khan","year":"2020","journal-title":"IEEE Access"}],"container-title":["Journal of Sensor and Actuator Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2224-2708\/10\/2\/25\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T14:10:30Z","timestamp":1760364630000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2224-2708\/10\/2\/25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,3,30]]},"references-count":59,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2021,6]]}},"alternative-id":["jsan10020025"],"URL":"https:\/\/doi.org\/10.3390\/jsan10020025","relation":{},"ISSN":["2224-2708"],"issn-type":[{"value":"2224-2708","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,3,30]]}}}