以剧本为导向的网络反应

A. Applebaum, Shawn Johnson, Michael Limiero, Michael Smith
{"title":"以剧本为导向的网络反应","authors":"A. Applebaum, Shawn Johnson, Michael Limiero, Michael Smith","doi":"10.1109/NCS.2018.00007","DOIUrl":null,"url":null,"abstract":"Cyber analysts tend to respond to anomalous events manually, often using subjective judgment that can lead to responses that are less than optimal. Additionally, analysts tend to report on events and share cyber knowledge in unstructured, textual formats, which not only require more time to parse – thus taking more time to respond – but also lead to multiple conclusions from the same input. To remedy this, we have proposed a framework designed to provide an analyst with a set of timely and accurate courses of action in response to events, in some cases automating those responses. As part of this framework, we have created a playbook specification format that allows analysts to specify the right course of action to take in response to events, given certain risk conditions and mission context. In addition to providing the specification format, we have also created an initial ontology to help analysts build their playbook contents and have laid out a notional architecture that can operationalize these playbooks. Our playbook format can help standardize how analysts should respond to events, thus decreasing the time to response and enabling analysts to share key knowledge in a common format. Ultimately, this should increase the efficacy of security operations center personnel.","PeriodicalId":283240,"journal":{"name":"2018 National Cyber Summit (NCS)","volume":"145 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":"{\"title\":\"Playbook Oriented Cyber Response\",\"authors\":\"A. Applebaum, Shawn Johnson, Michael Limiero, Michael Smith\",\"doi\":\"10.1109/NCS.2018.00007\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Cyber analysts tend to respond to anomalous events manually, often using subjective judgment that can lead to responses that are less than optimal. Additionally, analysts tend to report on events and share cyber knowledge in unstructured, textual formats, which not only require more time to parse – thus taking more time to respond – but also lead to multiple conclusions from the same input. To remedy this, we have proposed a framework designed to provide an analyst with a set of timely and accurate courses of action in response to events, in some cases automating those responses. As part of this framework, we have created a playbook specification format that allows analysts to specify the right course of action to take in response to events, given certain risk conditions and mission context. In addition to providing the specification format, we have also created an initial ontology to help analysts build their playbook contents and have laid out a notional architecture that can operationalize these playbooks. Our playbook format can help standardize how analysts should respond to events, thus decreasing the time to response and enabling analysts to share key knowledge in a common format. Ultimately, this should increase the efficacy of security operations center personnel.\",\"PeriodicalId\":283240,\"journal\":{\"name\":\"2018 National Cyber Summit (NCS)\",\"volume\":\"145 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-06-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"4\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2018 National Cyber Summit (NCS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/NCS.2018.00007\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 National Cyber Summit (NCS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/NCS.2018.00007","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

摘要

网络分析师倾向于手动响应异常事件,通常使用主观判断,这可能导致不太理想的响应。此外,分析人员倾向于以非结构化的文本格式报告事件和分享网络知识,这不仅需要更多的时间来分析——因此需要更多的时间来回应——而且还会从相同的输入中得出多个结论。为了解决这个问题,我们提出了一个框架,旨在为分析师提供一组及时和准确的行动方案,以响应事件,在某些情况下自动化这些响应。作为这个框架的一部分,我们已经创建了一个剧本规范格式,它允许分析人员在给定特定的风险条件和任务上下文的情况下,指定响应事件所采取的正确行动。除了提供规范格式之外,我们还创建了一个初始本体,以帮助分析人员构建他们的剧本内容,并制定了一个可以对这些剧本进行操作的概念体系结构。我们的剧本格式可以帮助标准化分析人员应该如何响应事件,从而减少响应时间,并使分析人员能够以公共格式共享关键知识。最终,这将提高安全运营中心人员的效率。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Playbook Oriented Cyber Response
Cyber analysts tend to respond to anomalous events manually, often using subjective judgment that can lead to responses that are less than optimal. Additionally, analysts tend to report on events and share cyber knowledge in unstructured, textual formats, which not only require more time to parse – thus taking more time to respond – but also lead to multiple conclusions from the same input. To remedy this, we have proposed a framework designed to provide an analyst with a set of timely and accurate courses of action in response to events, in some cases automating those responses. As part of this framework, we have created a playbook specification format that allows analysts to specify the right course of action to take in response to events, given certain risk conditions and mission context. In addition to providing the specification format, we have also created an initial ontology to help analysts build their playbook contents and have laid out a notional architecture that can operationalize these playbooks. Our playbook format can help standardize how analysts should respond to events, thus decreasing the time to response and enabling analysts to share key knowledge in a common format. Ultimately, this should increase the efficacy of security operations center personnel.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Design and Development of Smart TV Protector Message from General Chairs Title Page iii Publisher's Information An Exploratory Analysis on Cybersecurity Ecosystem Utilizing the NICE Framework
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1