首页> 外文会议>2013 IEEE International Conference on Technologies for Homeland Security >The CERT assessment tool: Increasing a security incident responder's ability to assess risk
【24h】

The CERT assessment tool: Increasing a security incident responder's ability to assess risk

机译:CERT评估工具:提高安全事件响应者评估风险的能力

获取原文
获取原文并翻译 | 示例

摘要

We set out to create an assessment and situational awareness tool for incident response. Extracting the risk assessment expertise and creating a systemic step-by-step workflow that could be followed by non-experts was challenging; however, what proved to be even more difficult was the mapping of that workflow to a common, natural language used by non-experts while still supporting the incident response. We at the Digital Intelligence and Investigation Directorate (DIID) have developed a way to maintain the velocity of incident response through the creation of a feed-forward decision support system to assist a security responder deal with the scale and challenges of assessing risk in critical information systems. Unfortunately, many applications fall short of expectations because the technology is used inappropriately: the wrong tool applied in the wrong way. Taking interaction techniques combined with a decision support system and applying them to one particularly demanding area — security incident response — leads to the conclusion that there is a proper and formal way to approach maintaining situational awareness in this complex domain. The CERT Assessment Tool increases a security incident responder's ability to assess risk and identify the incident response plan of critical information systems. The interface has four primary affordances to the user: (1) digital storage of the collected interview data with tagging of the information to create meta data of the objects as well as standardize terminology by reusing objects, (2) structured data that enables situational awareness of all systems on site and flexibility and recursion of system attributes, (3) guidance questions that provide runtime support for the system currently being assessed and a general direction to better assess each system based on historical data, and (4) real-time rules that make recommendations to the user through ‘push’ notifications, which enables a user to- identify and mitigate risk in information systems security affecting the safety of a system or the implementation of the security plan. The creation of a security decision support system framework to represent a series of steps to view the entire space of a security incident allows us to use techniques specifically designed or selected to align with one of the three identified stages of incident response — pre-incident (perception), during the event (comprehension), or after the event (projection). This combination of rules based on machine learning and push notifications are a first step in how computers will be able to support and advance the decision support technologies that are the backbone of this system.
机译:我们着手为事故响应创建评估和态势感知工具。提取风险评估专业知识并创建系统的分步工作流,非专家可以遵循该工作流;然而,事实证明,更困难的是将工作流映射到非专家使用的通用自然语言,同时仍支持事件响应。我们数字情报与调查局(DIID)已开发出一种方法,可通过创建前馈决策支持系统来维持事件响应的速度,以帮助安全响应者应对评估关键信息中的风险的规模和挑战。系统。不幸的是,由于该技术使用不当,许多应用程序达不到预期:错误的工具以错误的方式应用。将交互技术与决策支持系统结合起来,并将其应用于一个特别苛刻的领域(安全事件响应),得出的结论是,在这种复杂的领域中,存在一种适当且正式的方法来维持态势感知。 CERT评估工具提高了安全事件响应者评估风险和确定关键信息系统的事件响应计划的能力。该界面为用户提供了四个主要功能:(1)收集所收集的采访数据并对其进行标记,以创建对象的元数据,并通过重用对象来标准化术语;(2)能够情境感知的结构化数据现场的所有系统以及系统属性的灵活性和递归性;(3)为当前正在评估的系统提供运行时支持的指导性问题,以及根据历史数据更好地评估每个系统的总体指导,以及(4)实时规则通过“推送”通知向用户提出建议,使用户能够识别并减轻影响系统安全或安全计划实施的信息系统安全风险。创建安全决策支持系统框架以表示查看安全事件整个空间的一系列步骤,使我们能够使用经过专门设计或选择的技术,以与确定的事件响应三个阶段之一(事件发生前(感知),事件期间(理解)或事件之后(投影)。基于机器学习和推送通知的规则的这种组合是计算机将如何支持和推进作为该系统骨干的决策支持技术的第一步。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号