首页> 外文会议>Human Factors and Ergonomics Society;Human Factors and Ergonomics Society annual meeting >Simulation of Workflow and Threat Characteristics for Cyber Security Incident Response Teams
【24h】

Simulation of Workflow and Threat Characteristics for Cyber Security Incident Response Teams

机译:网络安全事件响应团队的工作流程和威胁特征的仿真

获取原文

摘要

Within large organizations, the defense of cyber assets generally involves the use of various mechanisms,such as intrusion detection systems, to alert cyber security personnel to suspicious network activity.Resulting alerts are reviewed by the organization’s cyber security personnel to investigate and assess thethreat and initiate appropriate actions to defend the organization’s network assets. While automatedsoftware routines are essential to cope with the massive volumes of data transmitted across data networks,the ultimate success of an organization’s efforts to resist adversarial attacks upon their cyber assets relieson the effectiveness of individuals and teams. This paper reports research to understand the factors thatimpact the effectiveness of Cyber Security Incidence Response Teams (CSIRTs). Specifically, asimulation is described that captures the workflow within a CSIRT. The simulation is then demonstrated ina study comparing the differential response time to threats that vary with respect to key characteristics(attack trajectory, targeted asset and perpetrator). It is shown that the results of the simulation correlatewith data from the actual incident response times of a professional CSIRT.
机译:在大型组织内部,网络资产的防御通常涉及各种机制的使用, 例如入侵检测系统,以提醒网络安全人员可疑的网络活动。 该组织的网络安全人员会审核由此产生的警报,以调查和评估 威胁并采取适当的措施来保护组织的网络资产。自动化时 软件例程对于处理跨数据网络传输的海量数据至关重要, 组织抵制对其网络资产进行对抗性攻击的努力的最终成功取决于 关于个人和团队效力的问题。本文进行了研究,以了解造成这种情况的因素 影响网络安全事件响应团队(CSIRT)的效率。具体来说, 描述了捕获CSIRT中的工作流程的模拟。然后在 一项研究比较了针对关键特征变化的威胁的差异响应时间 (攻击轨迹,目标资产和犯罪者)。结果表明,仿真结果具有相关性 来自专业CSIRT的实际事件响应时间的数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号