首页> 外文学位 >Identifying Challenges in Cybersecurity Incident Response: A Generic Qualitative Inquiry
【24h】

Identifying Challenges in Cybersecurity Incident Response: A Generic Qualitative Inquiry

机译:识别网络安全事件响应中的挑战:通用定性调查

获取原文
获取原文并翻译 | 示例

摘要

The purpose of this generic qualitative inquiry study was to research the barriers cybersecurity professionals face in receiving timely and accurate intelligence information regarding cyberattacks. There is a gap in current literature regarding what obstacles cybersecurity professionals face when trying to detect and deter cybercrime. The research question asked: "How do information security professionals describe their challenges in receiving timely and accurate cyber threat intelligence information?" The generic qualitative study used semi-structured interviews to collect information from study participants. Eight participants were interviewed to discern the challenges cybersecurity professionals encountered in receiving timely cyberattack threat information. The participants were all United States residents employed in the areas of cybersecurity, with at least 3 years of experience and had utilized actional cyber threat information sharing within the last year. Interview transcripts were analyzed to determine reoccurring themes using an open-coding process. The following three themes emerged: (a) the volume and nature of the data, (b) the constraints of time, and (c) trust. The key findings suggest that there are many similarities between cybersecurity defense and the theory of warning intelligence. There are many opportunities for improvement within cybersecurity defense utilizing shared intelligence and security automation. Intelligence sharing between agencies and security automation would assist cybersecurity professionals with a greater ability to detect and deter cyberattacks. The identified themes provide a foundation for future research into ways that information sharing, and security automation can reduce the amount of time it takes to detect and deter cyberattacks.
机译:这项通用定性调查研究的目的是研究网络安全专业人员在及时准确地接收有关网络攻击的情报信息方面面临的障碍。关于网络安全专业人员在尝试检测和阻止网络犯罪时面临的障碍,目前的文献中存在空白。研究问题提出:“信息安全专业人员如何描述他们在接收及时准确的网络威胁情报信息方面面临的挑战?通用定性研究使用半结构化访谈从研究参与者那里收集信息。八名参与者接受了采访,以辨别网络安全专业人员在及时接收网络攻击威胁信息时遇到的挑战。参与者都是受雇于网络安全领域的美国居民,具有至少 3 年的经验,并在过去一年内利用了行动网络威胁信息共享。使用开放编码过程分析访谈记录以确定重复出现的主题。出现了以下三个主题:(a) 数据的数量和性质,(b) 时间的限制,以及 (c) 信任。主要发现表明,网络安全防御与预警情报理论之间存在许多相似之处。利用共享情报和安全自动化,网络安全防御存在许多改进机会。机构之间的情报共享和安全自动化将有助于网络安全专业人员更强地检测和阻止网络攻击。确定的主题为未来研究信息共享和安全自动化如何减少检测和阻止网络攻击所需的时间奠定了基础。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号