首页> 外文会议>IEEE International Conference on Electro Information Technology >CARVE: A Scientific Method-Based Threat Hunting Hypothesis Development Model
【24h】

CARVE: A Scientific Method-Based Threat Hunting Hypothesis Development Model

机译:雕刻:基于科学方法的威胁狩猎假说发展模型

获取原文

摘要

A threat hunting exercise is a hypothesis driven exploratory and explanatory research process, the exercise is inherently scientific in nature and lends itself to the application of the scientific method of hypothesis development. The exercise commences with exploratory steps in the threat hypothesis phase to develop a logical argument asserting an existential threat, then follows with explanatory steps in the threat hunt phase to validate the argument. To deem a threat credible, that is, valid and relevant, a threat hunting hypothesis must establish a correlational and causal relationship between the asserted threat and a targeted asset, the hypothesis must adhere to the constructs of the scientific method for the exercise to be defined and measured objectively, and yield valuable and repeatable outcomes. Lack of adherence to the scientific method increases the frequency of invalid and/or irrelevant propositions in threat hypotheses, which diminishes Return on Investment (ROI) in cybersecurity defensive efforts due to wasted cycles of threat hunting exercises. This paper proposes a scientific method-based model, Collect Analyze Relate Validate Establish (CARVE), which can be used to develop valid and relevant threat hunting hypotheses in the context of a given organization's information system and environment. The CARVE model is defined by the following five steps: Collect, Analyze, Relate, Validate, and Establish. The effectiveness of the model is demonstrated using a case study based on the technical alert United States Computer Emergency Readiness Team (US CERT) TA17-293A.
机译:威胁狩猎运动是一​​个假设驱动的探索性和解释性研究过程,本身性质本质上是科学的,并赋予了科学假设发展的应用。练习在威胁假设阶段开始探讨阶梯,以开发逻辑参数,这些论点断言存在威胁,然后在威胁狩猎阶段的解释性步骤进行验证,以验证参数。为了认为威胁可靠,即有效和相关,威胁狩猎假设必须在主张的威胁和目标资产之间建立相关性和因果关系,假设必须遵守要定义的运动的科学方法构建客观地测量,并产生有价值和可重复的结果。缺乏对科学方法的依从性增加了威胁假设中无效和/或无关命题的频率,这减少了由于浪费狩猎锻炼的浪费循环而减少了网络安全防御性努力的投资回报(ROI)。本文提出了一种基于科学方法的模型,收集分析与验证建立(Carve),可以用于在给定的组织信息系统和环境的背景下制定有效和相关的威胁狩猎假设。 Carve模型由以下五个步骤定义:收集,分析,相关,验证和建立。根据基于技术警报美国计算机紧急准备团队(US CERT)TA17-293A的案例研究,使用案例研究证明了该模型的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号