首页> 外文会议>International Conference on Cyber Situational Awareness, Data Analytics and Assessment >Development and evaluation of information elements for simplified cyber-incident reports
【24h】

Development and evaluation of information elements for simplified cyber-incident reports

机译:开发和评估信息元素以简化网络事件报告

获取原文

摘要

One of the most important tasks in cyber security incident handling is to report what has occurred. Several frameworks have been developed to support this reporting, all with their own pros and cons. As a first step in the development of a practically useful incident description standard, we set to determine the appropriateness of sixteen plausible information elements relating to traceability and analysis. The information elements were evaluated during an exercise with 30 professional IT administrators and cyber security specialists with experience from cyber incident handling. In the exercise, the participants were instructed to report cyber threats and incidents in their assigned networks and evaluated based on their reporting. The evaluation assessed the extent to which the proposed information elements were used in the reports, if the sixteen information elements correlate with the quality of the incident reports, and the participants' subjective experiences of using the elements. The results show that the usage ratio of information elements varies a lot both between different reporters and between incidents. Further, the number of information elements used in a report correlated with the exercise management's quality assessments. Finally, the results reveal that although the overall assessment of content relevance of the simplified cyber-incident reporting template was positive, there is need for further validation of the template.
机译:网络安全事件处理中最重要的任务之一是报告发生了什么。已经开发了几个框架来支持这一报告,所有这些都具有自身利弊。作为发展实际上有用的事件描述标准的第一步,我们设定了确定与可追溯性和分析有关的十六个合理信息元素的适当性。信息要素在练习期间进行了评估,其中包含30名专业IT管理员和网络安全专家,网络事件处理的经验。在练习中,参与者被指示向其指定的网络中的网络威胁和事件报告网络威胁和事件,并根据其报告进行评估。如果十六个信息元素与事件报告的质量相关联,则评估评估报告中拟议的信息要素在报告中使用的程度,以及参与者使用该要素的主观经验。结果表明,不同记者与事件之间的信息元素的使用率变化很大。此外,报告中使用的信息元素的数量与锻炼管理的质量评估相关。最后,结果表明,虽然简化网络事件报告模板的内容相关性的整体评估是阳性的,但需要进一步验证模板。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号