首页> 外文学位 >Challenges to Adversarial Interplay Under High Uncertainty: Staged-World Study of a Cyber Security Event
【24h】

Challenges to Adversarial Interplay Under High Uncertainty: Staged-World Study of a Cyber Security Event

机译:高度不确定性下对抗性互动的挑战:网络安全事件的分阶段研究

获取原文
获取原文并翻译 | 示例

摘要

The vulnerability of critical and valued digital infrastructures and the difficulty of defending networks against attacks are a growing concern throughout domains. While numerous efforts exist to improve cyber defense through technological advances, human-centered research to uncover and address the difficulties experienced by network defenders is recent and still limited. Moreover, understanding cyber security, a fundamentally adversarial domain, requires investigations of the interrelated defense and attack processes, but such studies are rare. The dissertation presents results from a staged-world study of an adversarial cyber security exercise. This daylong exercise involved forty participants divided into an outside attacking team and a defending team operating in a simulated production environment.;The first objective is to identify critical skills and forms of expertise of cyber security as a domain of practice. Designed by cyber security experts, the exercise allowed for the investigation of core dimensions of cyber events, which have seen limited empirical study in past work on cyber defense: (1) decision-making in cyber defense; (2) network security within larger production structures and processes; (3) decision-making in cyber attack; and (4) interplay of attack and defense.;The second objective of the research is to discuss the approach designed and implemented in order to capture and analyze the cyber event observed. Challenges result especially from the scale of the processes to be tracked (attack and defense; number of participants; distribution of participants in teams, roles and space; duration of the exercise). The study we conducted aimed at exploring the domain of cyber security with an emphasis on the methodological dimensions of such investigation. Given the partially novel character of the research, a critical account of choices made, successes and pitfalls experienced aims at informing future advancements in the domain.;The third objective is to connect this study of the particular domain of cyber security to other studies of work in real-world situations. Relevant theoretical frameworks include: decision-making under uncertainty, distributed anomaly response, joint activity, perception of intent, and more generally Resilience Engineering. Making this link allows for the discussion of potential directions to improve cyber defense, as well as to further develop these theoretical frameworks. Cyber security, because of its nature and the typical challenges associated, constitutes a rich environment for such purposes.
机译:关键且有价值的数字基础架构的脆弱性以及防御网络抵御攻击的难度在整个领域中都日益引起关注。尽管人们为通过技术进步来改善网络防御做出了许多努力,但是以人为中心的发现和解决网络防御者所遇到的困难的研究是最近的并且仍然是有限的。此外,了解网络安全(从根本上是对抗性的领域)要求对相互关联的防御和攻击过程进行调查,但是这种研究很少。本文提出了一项对抗性网络安全演习的分阶段研究的结果。这项为期一天的演习涉及四十名参与者,分为在模拟生产环境中运作的外部攻击团队和防御团队。第一个目标是确定网络安全的关键技能和专业知识形式作为实践领域。该练习是由网络安全专家设计的,它允许对网络事件的核心方面进行调查,在过去有关网络防御的工作中,实证研究十分有限:(1)网络防御的决策; (2)较大的生产结构和过程中的网络安全性; (三)网络攻击决策; (4)攻击和防御的相互作用。研究的第二个目的是讨论设计和实施的方法,以捕获和分析观察到的网络事件。挑战尤其来自于要跟踪的流程的规模(攻击和防御;参与者的数量;参与者在团队,角色和空间中的分布;演习的持续时间)。我们进行的研究旨在探索网络安全领域,重点是这种调查的方法论层面。考虑到这项研究的部分新颖性,对所做选择,成功和陷阱的关键描述旨在告知该领域的未来进展。第三个目标是将这一对网络安全特定领域的研究与其他工作研究联系起来在现实世界中的情况。相关的理论框架包括:不确定性下的决策,分布式异常响应,联合活动,意图感知以及更广泛的弹性工程。建立此链接允许讨论改善网络防御的潜在方向,以及进一步发展这些理论框架。网络安全由于其性质和相关的典型挑战而构成了用于此目的的丰富环境。

著录项

  • 作者

    Branlat, Matthieu.;

  • 作者单位

    The Ohio State University.;

  • 授予单位 The Ohio State University.;
  • 学科 Systems science.;Computer science.
  • 学位 Ph.D.
  • 年度 2011
  • 页码 172 p.
  • 总页数 172
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号