EAGER: SaTC: Early-Stage Interdisciplinary Collaboration: Collaborative: A Sociotechnical Metrics Framework for Network and Security Operations Centers
EAGER: SaTC: Early-Stage Interdisciplinary Collaboration: Collaborative: A Sociotechnical Metrics Framework for Network and Security Operations Centers
批准号:
1915824
负责人:
Alexandru Bardas
金额:
$15.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-06-01 至 2022-05-31
中文摘要
网络和安全运营中心(SOC)是现代企业网络的核心组件。SoC管理网络运营、防御网络威胁并维护法规遵从性。通常,管理和SOC操作员使用监控软件和指标(例如未结和已关闭票据)来管理SOC效率。这些指标可能无法代表SOC的实际有效性和网络的安全态势。该项目将研究改进的指标如何更好地激励生产例程,揭示网络中潜在的基本安全漏洞,并在控制组织中触发稳定的正确规模调整流程。该项目将为学生提供一个参与安全操作研究的机会,从而鼓励他们从事安全研究或专业工作。该项目将开发一个新的度量框架,针对企业网络安全来衡量和验证SOC性能。具体目标是创建一个框架,SOC和上级组织人员可以使用该框架为其独特的安全环境创建量身定制的指标。这项研究包括对网络监测的技术研究,以及对组织环境研究的定性方法,该方法将人和技术作为复杂系统中相互作用的组成部分进行分析,并描述这些系统运行或失灵的稳定性和变化。通过将网络、安全组件和运营人员视为相互依赖的系统的一部分,这些指标将能够考虑到突出的安全漏洞、战略和长期规划以及选民利益等因素,并将为现场SOC分析师提供方法,将当地知识输入更高级别的决策。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Network and Security Operations Centers (SOCs) are central components of modern enterprise networks. SOCs manage network operations, defend against cyber threats, and maintain regulatory compliance. Typically, management and SOC operators use monitoring software and metrics, such as open and closed tickets, to manage SOC efficiency. These metrics may fail to represent the real effectiveness of the SOC and the security posture of the network. This project will study how improved metrics could better incentivize productive routines, reveal potentially fundamental security vulnerabilities in the network, and trigger stabilizing right-sizing processes in the controlling organization. The project will afford an opportunity for students to participate in research on security operations and thereby encourage careers in security research or professions.This project will develop a new metrics framework that measures and validates SOC performance against enterprise network security. The specific goal is to create a framework that SOCs and parent organization personnel could use to create tailored metrics for their unique security environment. The research includes a technical study of network monitoring, as well as a qualitative approach to the study of organizational environments that analyzes people and technological artifacts as interacting components in complex systems and describes stability and change in the functioning or mis-functioning of these systems. By treating networks, security components, and operations staff as part of an interdependent system, the metrics will be able to account for factors such as outstanding security vulnerabilities, strategic and long-term planning, and constituency interests, and will provide on-the-ground SOC analysts with ways to input local knowledge into higher-up decisions.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/3372297.3423346
发表时间:
2020-10
期刊:
Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Kailani R. Jones;T. Yen;S. C. Sundaramurthy;Alexandru G. Bardas]
通讯作者:
Kailani R. Jones;T. Yen;S. C. Sundaramurthy;Alexandru G. Bardas
DOI:
10.1109/sp40001.2021.00055
发表时间:
2021
期刊:
Proceedings of the IEEE Symposium on Security and Privacy
影响因子:
--
作者:
[Daffalla, Alaa, Simko, Lucy, Kohno, Tadayoshi, Bardas, Alexandru G]
通讯作者:
Bardas, Alexandru G
CAREER: SaTC: Bridging the Gap Between Research and Practice: Automation and Metrics in Security Operation Centers
-
批准号:2143393
-
项目类别:Continuing Grant
-
资助金额:$52.43万
-
财政年份:2022
-
负责人:Alexandru Bardas
-
依托单位:
CRII: SaTC: Creating and Managing Structurally-Morphing IT Systems - Moving Targets
-
批准号:1850406
-
项目类别:Standard Grant
-
资助金额:$17.49万
-
财政年份:2019
-
负责人:Alexandru Bardas
-
依托单位:
海外基金