首页> 外文会议>Conference on Resilience Week >Adapting level of detail in user interfaces for Cybersecurity operations
【24h】

Adapting level of detail in user interfaces for Cybersecurity operations

机译:调整用户界面中的详细程度以进行网络安全操作

获取原文

摘要

As cybersecurity threats increasingly appear in news headlines, the security industry continues to build state of the art firewall and intrusion detection systems for monitoring activities in complex cyber networks. These systems generate millions of log files and continuous alerts. In order to make sense of cyber data, cyber security and system administrators review and analyze millions of logs using highly summarized views and manual cycles of click-intensive details-on-demand. This is laborious, induces cognitive overload, and is prone to errors resulting in important information and impacts not being seen when most needed. Our research focus is on developing “FocalPoint” a system that provides Adaptive Level of Detail (LOD) in user interfaces for cybersecurity operations. FocalPoint is a recommender system tailored for complex network information structures that reasons about contextual information associated with the network, user tasks, and cognitive load. This facilitates tuning cyber visualization displays thereby improving user performance in perception, comprehension and projection of current Cybersecurity Situational Awareness (Cyber SA). For cyber analysts, having the right information, in context, when most needed without cognitive overload could lead to effective decision making in cyber operations. We provide a use case scenario for FocalPoint with an in-progress prototype and highlight various challenges and potential considerations for building an effective adaptive system.
机译:随着网络安全威胁越来越多地出现在新闻头条中,安全行业继续建立最先进的防火墙和入侵检测系统,以监视复杂网络中的活动。这些系统生成数百万个日志文件和连续警报。为了理解网络数据,网络安全和系统管理员使用高度汇总的视图和按需单击的详细信息的手动循环来查看和分析数百万条日志。这很费力,会导致认知超负荷,并且容易出错,从而导致在最需要时看不到重要的信息和影响。我们的研究重点是开发“ FocalPoint”系统,该系统在用户界面中为网络安全运营提供自适应详细程度(LOD)。 FocalPoint是为复杂的网络信息结构量身定制的推荐系统,该结构会考虑与网络,用户任务和认知负荷相关的上下文信息。这有助于调整网络可视化显示,从而提高用户在感知,理解和预测当前网络安全状况感知(Cyber​​ SA)方面的性能。对于网络分析人员而言,在最需要的情况下没有认知超负荷的情况下,在适当的上下文中拥有正确的信息可能会导致网络运营中的有效决策。我们通过一个正在进行的原型为FocalPoint提供了一个用例场景,并重点介绍了构建有效的自适应系统时所面临的各种挑战和潜在考虑因素。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号