Determining System Requirements for Human-Machine Integration in Cyber Security Incident Response

Determining System Requirements for Human-Machine Integration in Cyber Security Incident Response
复制标题

确定网络安全事件响应中人机集成的系统要求

DOI:
--
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
Megan Nyre
Megan Nyre
中科院分区:
--
文献类型:
--
作者:
Megan Nyre

文献摘要

被引文献

相似文献

2019年,网络安全被认为是全球经济和国家安全面临的最大威胁之一。美国的主要机构已经认识到这一事实,并就该领域的战略优先事项和未来举措提供了指导。然而,人们仍然缺乏对影响网络防御工作的复杂性、范围和有效性的因素的基本了解。计算机安全事件响应是检测、识别、缓解和解决网络潜在安全威胁的短期过程。这些活动通常在计算机安全事件响应团队(CSIRT)中进行,该团队由人类分析师组成,这些分析师被组织成分层结构,并与许多不同的计算工具和程序密切合作。尽管CSIRT通常为网络提供第一道防线,但目前全球分析师严重短缺,无法填补空缺职位。由于在满足需求方面的时间滞后和相关成本,从教育和技术角度进行的研究和开发努力在解决这一短缺方面一直是无效的。本论文探讨了如何联合收割机这两种方法,考虑如何以人为本的研究可以告知发展的计算解决方案,以增强人类分析师的能力。结合这些方法的更大目标是有效地补充人类的专业知识与技术能力,以减轻来自技能短缺的压力。通过三项研究开发了混合系统的见解和设计建议,以推进当前的安全自动化状态。第一项研究是一项人种学实地研究,重点是收集和分析来自不同部门的三个不同CSIRT的背景数据;范围超出了个人事件响应任务,包括团队内的组织和信息共享方面。分析揭示了更大的设计影响,在不同的团队环境中的协作和协调,以及自动化的实用性和采用的考虑。第二项研究是一个认知任务分析与CSIR专家与不同背景的访谈集中在CSIRTs的信息共享任务的专业知识要求。输出利用维度专业知识结构来识别和优先考虑潜在的专业领域,以通过自动化工具和功能进行增强。研究3包括基于研究2中确定的专业领域对当前自动化平台的市场分析,并使用系统工程方法为未来的系统开发概念和功能架构所有三项研究的结果都支持CSIR混合自动化发展的未来方向,方法是确定安全性中传统工具设计之外的社会和组织因素,系统集成。此外,本论文还提供了自动化技术的功能考虑,可以增强人类在事件响应中的能力;这些功能支持人类之间以及人类与技术系统之间更好的信息共享。通过在CSIR中追求人-系统集成,研究可以通过确定自动化可以动态帮助信息共享和专业知识发展的地方来帮助缓解技能短缺。未来的研究可以扩展CSIR的专业知识框架,并在其他领域扩展建议的增强功能的应用。
In 2019, cyber security is considered one of the most significant threats to the global economy and national security. Top U.S. agencies have acknowledged this fact, and provided direction regarding strategic priorities and future initiatives within the domain. However, there is still a lack of basic understanding of factors that impact complexity, scope, and effectiveness of cyber defense efforts. Computer security incident response is the short-term process of detecting, identifying, mitigating, and resolving a potential security threat to a network. These activities are typically conducted in computer security incident response teams (CSIRTs) comprised of human analysts that are organized into hierarchical tiers and work closely with many different computational tools and programs. Despite the fact that CSIRTs often provide the first line of defense to a network, there is currently a substantial global skills shortage of analysts to fill open positions. Research and development efforts from educational and technological perspectives have been independently ineffective at addressing this shortage due to time lags in meeting demand and associated costs. This dissertation explored how to combine the two approaches by considering how human-centered research can inform development of computational solutions toward augmenting human analyst capabilities. The larger goal of combining these approaches is to effectively complement human expertise with technological capability to alleviate pressures from the skills shortage.Insights and design recommendations for hybrid systems to advance the current state of security automation were developed through three studies. The first study was an ethnographic field study which focused on collecting and analyzing contextual data from three diverse CSIRTs from different sectors; the scope extended beyond individual incident response tasks to include aspects of organization and information sharing within teams. Analysis revealed larger design implications regarding collaboration and coordination in different team environments, as well as considerations about usefulness and adoption of automation. The second study was a cognitive task analysis with CSIR experts with diverse backgrounds; the interviews focused on expertise requirements for information sharing tasks in CSIRTs. Outputs utilized a dimensional expertise construct to identify and prioritize potential expertise areas for augmentation with automated tools and features. Study 3 included a market analysis of current automation platforms based on the expertise areas identified in Study 2, and used Systems Engineering methodologies to develop concepts and functional architectures for future system (and feature) development.Findings of all three studies support future directions for hybrid automation development in CSIR by identifying social and organizational factors beyond traditional tool design in security that supports human-systems integration. Additionally, this dissertation delivered functional considerations for automated technology that can augment human capabilities in incident response; these functions support better information sharing between humans and between humans and technological systems. By pursuing human-systems integration in CSIR, research can help alleviate the skills shortage by identifying where automation can dynamically assist with information sharing and expertise development. Future research can expand upon the expertise framework developed for CSIR and extend the application of proposed augmenting functions in other domains.