首页> 外文会议>International Conference on Augmented Reality, Virual Reality and Computer Graphics >Alert Characterization by Non-expert Users in a Cybersecurity Virtual Environment: A Usability Study
【24h】

Alert Characterization by Non-expert Users in a Cybersecurity Virtual Environment: A Usability Study

机译:网络安全虚拟环境中非专家用户的警报特征:可用性研究

获取原文

摘要

Although cybersecurity is a domain where data analysis and training are considered of the highest importance, few virtual environments for cybersecurity are specifically developed, while they are used efficiently in other domains to tackle these issues. By taking into account cyber analysts' practices and tasks, we have proposed the 3D Cyber Common Operational Picture model (3D Cyber-COP), that aims at mediating analysts' activities into a Collaborative Virtual Environment (CVE), in which users can perform alert analysis scenarios. In this article, we present a usability study we have performed with non-expert users. We have proposed three virtual environments (a graph-based, an office-based, and the coupling of the two previous ones) in which users should perform a simplified alert analysis scenario based on the WannaCry ransomware. In these environments, users must switch between three views (alert, cyber and physical ones) which all contain different kinds of data sources. These data have to be used to perform the investigations and to determine if alerts are due to malicious activities or if they are caused by false positives. We have had 30 users, with no prior knowledge in cybersecurity. They have performed very well at the cybersecurity task and they have managed to interact and navigate easily. SUS usability scores were above 70 for the three environments and users have shown a preference towards the coupled environment, which was considered more practical and useful.
机译:尽管网络安全是最重要的数据分析和培训领域,但很少专门开发用于网络安全的虚拟环境,而在其他领域则有效地使用了虚拟环境来解决这些问题。通过考虑网络分析师的做法和任务,我们提出了3D网络通用运营图模型(3D Cyber​​-COP),该模型旨在将分析师的活动介导到协作虚拟环境(CVE)中,用户可以在其中执行警报分析方案。在本文中,我们介绍了针对非专家用户进行的可用性研究。我们提出了三个虚拟环境(基于图形的,基于办公室的以及之前两个环境的结合),在这些环境中,用户应基于WannaCry勒索软件执行简化的警报分析方案。在这些环境中,用户必须在三个视图(警报,网络和物理视图)之间切换,这些视图均包含不同种类的数据源。这些数据必须用于执行调查并确定警报是由于恶意活动引起还是由误报引起。我们有30位用户,但没有网络安全方面的知识。他们在网络安全任务中的表现非常出色,并且能够轻松地进行交互和导航。在这三个环境中,SUS可用性得分均高于70,并且用户显示出对耦合环境的偏爱,后者被认为更加实用和有用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号