Exploratory Analysis of Decision-Making Biases of Professional Red Teamers in a Cyber-Attack Dataset

IF 2.2 Q3 ENGINEERING, INDUSTRIAL Journal of Cognitive Engineering and Decision Making Pub Date : 2023-11-28 DOI:10.1177/15553434231217787
Robert S. Gutzwiller, Hansol Rheem, Kimberly J. Ferguson-Walter, Christina M. Lewis, Chelsea K. Johnson, M. Major
{"title":"Exploratory Analysis of Decision-Making Biases of Professional Red Teamers in a Cyber-Attack Dataset","authors":"Robert S. Gutzwiller, Hansol Rheem, Kimberly J. Ferguson-Walter, Christina M. Lewis, Chelsea K. Johnson, M. Major","doi":"10.1177/15553434231217787","DOIUrl":null,"url":null,"abstract":"Attacker psychology is currently under-examined in cybersecurity research. A prior, large-scale study sought to understand attackers’ behavior by testing both technological and psychological deception. Professional “red team” members participated over two days in various conditions. This data was examined for further evidence that cognitive biases, a potential disruption for attackers, may be present, and may be affecting the outcome. An applied, novel methodology for measuring confirmation bias and framing effects is presented using this realistic dataset. Both confirmation bias and the framing effect occurred in this interpretation. The framing effect appears to have reduced attacker interactions with systems in the network, which may benefit cyber defenders. These results provide additional, exploratory evidence that biases in the decision-making of cyber attackers could be used as part of a defensive cyber strategy. Limitations to the approach and directions for future study of attackers are discussed.","PeriodicalId":46342,"journal":{"name":"Journal of Cognitive Engineering and Decision Making","volume":null,"pages":null},"PeriodicalIF":2.2000,"publicationDate":"2023-11-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Cognitive Engineering and Decision Making","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1177/15553434231217787","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"ENGINEERING, INDUSTRIAL","Score":null,"Total":0}
引用次数: 0

Abstract

Attacker psychology is currently under-examined in cybersecurity research. A prior, large-scale study sought to understand attackers’ behavior by testing both technological and psychological deception. Professional “red team” members participated over two days in various conditions. This data was examined for further evidence that cognitive biases, a potential disruption for attackers, may be present, and may be affecting the outcome. An applied, novel methodology for measuring confirmation bias and framing effects is presented using this realistic dataset. Both confirmation bias and the framing effect occurred in this interpretation. The framing effect appears to have reduced attacker interactions with systems in the network, which may benefit cyber defenders. These results provide additional, exploratory evidence that biases in the decision-making of cyber attackers could be used as part of a defensive cyber strategy. Limitations to the approach and directions for future study of attackers are discussed.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
网络攻击数据集中专业红队人员决策偏差的探索性分析
目前,网络安全研究中对攻击者心理的研究不足。之前的一项大规模研究试图通过测试技术和心理欺骗来了解攻击者的行为。专业 "红队 "成员在各种条件下参加了为期两天的测试。研究人员对这些数据进行了检查,以进一步证明可能存在的认知偏差--攻击者的潜在干扰因素--可能会影响结果。利用这个真实的数据集,介绍了一种测量确认偏差和框架效应的应用新方法。在这次解读中,确认偏差和框架效应都出现了。框架效应似乎减少了攻击者与网络系统的互动,这可能有利于网络防御者。这些结果提供了更多探索性证据,表明网络攻击者决策中的偏差可被用作防御性网络战略的一部分。本文还讨论了该方法的局限性以及未来研究攻击者的方向。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
CiteScore
4.60
自引率
10.00%
发文量
21
期刊最新文献
Introduction to the Special Issue on Automation Failure Augmenting Human Cognition With a Digital Submarine Periscope Get on the Round Dial: Fighter Pilot Strategies for Recovering Situation Awareness After Disorienting Physiological Events Distinguishing Urgent From Non-urgent Communications: A Mixed Methods Study of Communication Technology Use in Perinatal Care Wrong, Strong, and Silent: What Happens when Automated Systems With High Autonomy and High Authority Misbehave?
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1