EAGER: SaTC: Early-Stage Interdisciplinary Collaboration: Collaborative: A Sociotechnical Metrics Framework for Network and Security Operations Centers
EAGER: SaTC: Early-Stage Interdisciplinary Collaboration: Collaborative: A Sociotechnical Metrics Framework for Network and Security Operations Centers
批准号:
1915824
负责人:
Alexandru Bardas
金额:
$15.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-06-01 至 2022-05-31
中文摘要
网络和安全操作中心(soc)是现代企业网络的核心组成部分。soc管理网络运营,防御网络威胁,并维护法规遵从性。通常,管理层和SOC运营商使用监控软件和指标(如打开和关闭票证)来管理SOC效率。这些指标可能无法代表SOC的真正有效性和网络的安全态势。该项目将研究改进的指标如何更好地激励生产流程,揭示网络中潜在的基本安全漏洞,并在控制组织中触发稳定的适当规模流程。该项目将为学生提供参与安全操作研究的机会,从而鼓励从事安全研究或专业工作。该项目将开发一个新的指标框架,根据企业网络安全来衡量和验证SOC性能。具体目标是创建一个框架,soc和上级组织人员可以使用该框架为其独特的安全环境创建定制的度量标准。该研究包括对网络监控的技术研究,以及对组织环境研究的定性方法,该方法分析人员和技术工件作为复杂系统中相互作用的组件,并描述这些系统功能或功能错误中的稳定性和变化。通过将网络、安全组件和操作人员视为一个相互依赖的系统的一部分,这些指标将能够考虑诸如突出的安全漏洞、战略和长期规划以及选民利益等因素,并将为现场SOC分析师提供将本地知识输入到高层决策的方法。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Network and Security Operations Centers (SOCs) are central components of modern enterprise networks. SOCs manage network operations, defend against cyber threats, and maintain regulatory compliance. Typically, management and SOC operators use monitoring software and metrics, such as open and closed tickets, to manage SOC efficiency. These metrics may fail to represent the real effectiveness of the SOC and the security posture of the network. This project will study how improved metrics could better incentivize productive routines, reveal potentially fundamental security vulnerabilities in the network, and trigger stabilizing right-sizing processes in the controlling organization. The project will afford an opportunity for students to participate in research on security operations and thereby encourage careers in security research or professions.This project will develop a new metrics framework that measures and validates SOC performance against enterprise network security. The specific goal is to create a framework that SOCs and parent organization personnel could use to create tailored metrics for their unique security environment. The research includes a technical study of network monitoring, as well as a qualitative approach to the study of organizational environments that analyzes people and technological artifacts as interacting components in complex systems and describes stability and change in the functioning or mis-functioning of these systems. By treating networks, security components, and operations staff as part of an interdependent system, the metrics will be able to account for factors such as outstanding security vulnerabilities, strategic and long-term planning, and constituency interests, and will provide on-the-ground SOC analysts with ways to input local knowledge into higher-up decisions.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/3372297.3423346
发表时间:
2020-10
期刊:
Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Kailani R. Jones;T. Yen;S. C. Sundaramurthy;Alexandru G. Bardas]
通讯作者:
Kailani R. Jones;T. Yen;S. C. Sundaramurthy;Alexandru G. Bardas
DOI:
10.1109/sp40001.2021.00055
发表时间:
2021
期刊:
Proceedings of the IEEE Symposium on Security and Privacy
影响因子:
--
作者:
[Daffalla, Alaa, Simko, Lucy, Kohno, Tadayoshi, Bardas, Alexandru G]
通讯作者:
Bardas, Alexandru G
CAREER: SaTC: Bridging the Gap Between Research and Practice: Automation and Metrics in Security Operation Centers
-
批准号:2143393
-
项目类别:Continuing Grant
-
资助金额:$52.43万
-
财政年份:2022
-
负责人:Alexandru Bardas
-
依托单位:
CRII: SaTC: Creating and Managing Structurally-Morphing IT Systems - Moving Targets
-
批准号:1850406
-
项目类别:Standard Grant
-
资助金额:$17.49万
-
财政年份:2019
-
负责人:Alexandru Bardas
-
依托单位:
海外基金