首页> 外文会议>IEEE International Conference on Collaboration and Internet Computing >The World (of CTF) is Not Enough Data: Lessons Learned from a Cyber Deception Experiment
【24h】

The World (of CTF) is Not Enough Data: Lessons Learned from a Cyber Deception Experiment

机译:(CTF的世界)数据不足:从网络欺骗实验中学到的教训

获取原文

摘要

The human side of cyber is fundamentally important to understanding and improving cyber operations. With the exception of Capture the Flag (CTF) exercises, cyber testing and experimentation tends to ignore the human attacker. While traditional CTF events include a deeply rooted human component, they rarely aim to measure human performance, cognition, or psychology. We argue that CTF is not sufficient for measuring these aspects of the human; instead, we examine the value in performing red team behavioral and cognitive testing in a large-scale, controlled human-subject experiment. In this paper we describe the pros and cons of performing this type of experimentation and provide detailed exposition of the data collection and experimental controls used during a recent cyber deception experiment-the Tularosa Study. Finally, we will discuss lessons learned and how our experiences can inform best practices in future cyber operations studies of human behavior and cognition.
机译:网络的人文方面对于理解和改善网络运营至关重要。除了“夺旗”(CTF)演习之外,网络测试和实验往往会忽略攻击者。传统的CTF事件虽然包含着根深蒂固的人类成分,但很少旨在衡量人类的表现,认知或心理。我们认为,CTF不足以衡量人类的这些方面。取而代之的是,我们在大规模,受控的人类受试者实验中检验了进行红队行为和认知测试的价值。在本文中,我们描述了进行这种类型的实验的利弊,并详细说明了在最近的网络欺骗实验-Tularosa研究中使用的数据收集和实验控制。最后,我们将讨论经验教训,以及我们的经验将如何在未来的网络运营研究中对人类行为和认知提供最佳实践信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号