首页> 外文会议>Data and applications security and privacy XXV >Cyber Situation Awareness: Modeling the Security Analyst in a Cyber-Attack Scenario through Instance-Based Learning
【24h】

Cyber Situation Awareness: Modeling the Security Analyst in a Cyber-Attack Scenario through Instance-Based Learning

机译:网络状况意识:通过基于实例的学习在网络攻击方案中对安全分析师进行建模

获取原文
获取原文并翻译 | 示例

摘要

In a corporate network, the situation awareness (SA) of a security analyst is of particular interest. A security analyst is in charge of observing the online operations of a corporate network (e.g., an online retail company with an external webserver and an internal fileserver) from threats of random or organized cyber-attacks. The current work describes a cognitive Instance-based Learning (IBL) model of the recognition and comprehension processes of a security analyst in a simple cyber-attack scenario. The IBL model first recognizes cyber-events (e.g., execution of a file on a server) in the network based upon events' situation attributes and the similarity of events' attributes to past experiences (instances) stored in analyst's memory. Then, the model reasons about a sequence of observed events being a cyber-attack or not, based upon instances retrieved from memory and the risk-tolerance of a simulated analyst. The execution of the IBL model generates predictions of the recognition and comprehension processes of security analyst in a cyber-attack. An analyst's decisions are evaluated in the model based upon two cyber SA metrics of accuracy and timeliness of analyst's decision actions. Future work in this area will focus on collecting human data to validate the predictions made by the model.
机译:在公司网络中,安全分析人员的态势感知(SA)特别重要。安全分析师负责观察公司网络(例如,具有外部Web服务器和内部文件服务器的在线零售公司)的在线操作,以免受随机或有组织的网络攻击的威胁。当前的工作描述了一个简单的网络攻击情况下安全分析师的识别和理解过程的基于认知实例的学习(IBL)模型。 IBL模型首先根据事件的情境属性以及事件的属性与分析师内存中存储的过去经验(实例)的相似性,识别网络中的网络事件(例如,服务器上文件的执行)。然后,基于从内存中检索到的实例和模拟分析师的风险承受能力,该模型会说明观察到的事件序列是否为网络攻击。 IBL模型的执行会生成对网络攻击中安全分析师的识别和理解过程的预测。在模型中,基于两个网络SA准确性和分析人员决策行动的及时性指标来评估分析人员的决策。该领域未来的工作将集中在收集人类数据上,以验证模型所做的预测。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号