The Effects of Security Management on Security Events

The Effects of Security Management on Security Events
复制标题

安全管理对安全事件的影响

DOI:
--
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
F. Nagle
F. Nagle
中科院分区:
--
文献类型:
--
作者:
F. Nagle

文献摘要

被引文献

相似文献

尽管安全管理期望的结果是更好的安全性,但这种关联的实证证据却很稀缺。这种稀缺源于在公司层面缺乏广泛样本公司的安全态势或安全事件的数据。为了解决这个问题,我们使用了一个新的数据集,该数据集包含了《财富》500强企业中480家企业的每日公司层面的安全信息,其中包含超过3300万个安全事件。这个从一家安全监测公司获得的数据集包含了294天期间安全管理的每日度量以及负面安全事件,产生了133248个公司/日的观测值。实证分析发现,公司开放端口的数量与僵尸网络活动、潜在利用和未经请求的通信的较高发生率相关,一些分析还显示与恶意软件活动存在关联。这些发现对于使用隐马尔可夫模型和分层线性模型的几种替代设定是稳健的。因此,本文为安全实践的一个基本假设——安全管理与安全性提高之间的联系找到了实证证据。
Although the desired outcome of security management is better security, empirical evidence for this link is scarce. The scarcity arises from lack of data at the firm level for either security posture or incidents across a broad sample of companies. To address this, we use a novel dataset of daily firm-level security information for 480 of the Fortune 500 enterprises that consists of over 33 million security events. The dataset, obtained from a security monitoring company, contains daily measures of security management and negative security events for a 294 day period, yielding 133,248 firm/day observations. Empirical analysis finds that the number of open ports in a firm is associated with higher incidences of botnet activity, potential exploitation, and unsolicited communications, with some analyses also showing a link to malware activity. The findings are robust to several alternative specifications using hidden Markov and hierarchical linear models. This paper thus finds empirical evidence for a fundamental assumption of security practice — a link between security management and improved security.