Jack pandemus – Cyber incident and emergency response during a pandemic

Jack pandemus – Cyber incident and emergency response during a pandemic
复制标题

Jack pandemus – 大流行期间的网络事件和紧急响应

DOI:
--
复制
发表时间:
2021
影响因子:
1.8
通讯作者:
Steven M. Whitham
Steven M. Whitham
中科院分区:
--
文献类型:
--
作者:
Erik B. Korn;Douglas M. Fletcher;Erica M. Mitchell;Aryn A. Pyke;Steven M. Whitham

文献摘要

被引文献

相似文献

摘要COVID-19迅速带来了一个新的广阔空间,带来了不可预见的脆弱性。网络威胁行为者迅速发现了这个空间,并立即开始在混乱的条件下抓住机会。认识到这一新出现的挑战,我们的目标是找到一种机制,以支持在疫情大流行的情况下更好地理解应急管理的整体网络事件响应。因此,我们进行了Jack Pandemus,这是一个模拟并发网络和紧急事件响应挑战的分布式事件。这一事件首先发生在南卡罗来纳州的查尔斯顿,其次是格鲁吉亚的萨凡纳。每次迭代都包括公共和私营部门实体,其位置与现实世界的网络事件和/或应急响应相对应。Jack Pandemus介绍了在大流行条件下发生的级联多部门网络事件,重点是确定跨部门的差距、依赖关系、限制因素、优势和经验教训。Jack Pandemus最终透露:大流行病的物理压力源可能会严重影响网络事件的应对;尽管同时存在网络后果,但应急反应仍然主要集中在大流行病的影响上;在多部门危机期间,当地共享的资源很快耗尽;公共和私营部门在如何以及何时请求额外支持方面仍然存在严重混乱;网络安全没有被视为一个业务问题,尽管有相当大的级联潜力。
ABSTRACT COVID-19 quickly gave rise to a newly expansive space wrought with unforeseen vulnerabilities. Cyber threat actors swiftly identified this space and immediately began seizing targets of opportunity amid chaotic conditions. Recognizing this emerging challenge, our goal was to find a mechanism that would support better understanding of holistic cyber incident response in the context of emergency management amid pandemic circumstances. Therefore, we conducted Jack Pandemus, a distributed event that simulated concurrent cyber and emergency incident response challenges. This event first occurred with Charleston, South Carolina followed by Savannah, Georgia. Each iteration included public and private sector entities whose positions corresponded with real-world cyber incident and/or emergency response. Jack Pandemus introduced a cascading multisector cyber incident under pandemic conditions with a focus on identifying cross-sector gaps, dependencies, constraints, strengths, and lessons learned. Jack Pandemus ultimately revealed: that physical pandemic stressors can significantly impact cyber incident response; that emergency response remains primarily focused on pandemic impacts despite concurrent cyber consequences; that locally shared resources are quickly exhausted during a multisector crisis; that significant confusion remains between public and private sectors regarding how and when to request additional support; and that cybersecurity is not treated as an operational problem despite considerable cascading potential.