首页> 外文会议>IEEE International Conference on Electro Information Technology >CARVE: A Scientific Method-Based Threat Hunting Hypothesis Development Model
【24h】

CARVE: A Scientific Method-Based Threat Hunting Hypothesis Development Model

机译:雕刻:基于科学方法的威胁狩猎假设发展模型

获取原文

摘要

A threat hunting exercise is a hypothesis driven exploratory and explanatory research process, the exercise is inherently scientific in nature and lends itself to the application of the scientific method of hypothesis development. The exercise commences with exploratory steps in the threat hypothesis phase to develop a logical argument asserting an existential threat, then follows with explanatory steps in the threat hunt phase to validate the argument. To deem a threat credible, that is, valid and relevant, a threat hunting hypothesis must establish a correlational and causal relationship between the asserted threat and a targeted asset, the hypothesis must adhere to the constructs of the scientific method for the exercise to be defined and measured objectively, and yield valuable and repeatable outcomes. Lack of adherence to the scientific method increases the frequency of invalid and/or irrelevant propositions in threat hypotheses, which diminishes Return on Investment (ROI) in cybersecurity defensive efforts due to wasted cycles of threat hunting exercises. This paper proposes a scientific method-based model, Collect Analyze Relate Validate Establish (CARVE), which can be used to develop valid and relevant threat hunting hypotheses in the context of a given organization's information system and environment. The CARVE model is defined by the following five steps: Collect, Analyze, Relate, Validate, and Establish. The effectiveness of the model is demonstrated using a case study based on the technical alert United States Computer Emergency Readiness Team (US CERT) TA17-293A.
机译:威胁狩猎运动是一​​个假设驱动的探索性和解释性研究的过程中,锻炼是在本质上是科学的和适合于假设的科学发展方法的应用。在威胁假说相探索步骤开发断言生存的威胁的逻辑参数的锻炼开始时,然后用在威胁狩猎相位说明步骤来验证参数如下。认为某一威胁可信的,那就是有效的,相关的,威胁狩猎假说必须建立断言威胁和有针对性的资产之间的相关性和因果关系,要定义的假设,必须坚持以科学方法的结构进行演练和客观测量,并产生有价值的和可重复的结果。缺乏坚持科学的方法提高了无效的和/或不相关的命题的威胁假设的频率,这在网络安全防御努力减少投资回报(ROI)由于威胁演习狩猎浪费周期。本文提出了一种科学的方法为基础的模型,收集分析相关验证建立(CARVE),可用于开发有效和相关威胁狩猎假设在一个给定的组织的信息系统和环境的上下文。中分模型由以下五个步骤确定:收集,分析,相关,验证和建立。该模型的有效性使用基于技术警报美国计算机应急准备小组(US CERT)TA17-293A的情况下,研究证实。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号