2020
DOI: 10.1145/3384471
|View full text |Cite
|
Sign up to set email alerts
|

Gaps and Opportunities in Situational Awareness for Cybersecurity

Abstract: Demand is present among security practitioners for improving cyber situational awareness (SA), but capability and assessment have not risen to match. SA is an integral component of cybersecurity for everyone from individuals to business to response teams and threat exchanges. In this Field Note, we highlight existing research and our field observations, a recent review of cyber SA research literature, and call upon the research community to help address three research problems in situational awareness for cybe… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
11
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
4
2
1

Relationship

0
7

Authors

Journals

citations
Cited by 30 publications
(13 citation statements)
references
References 27 publications
0
11
0
Order By: Relevance
“…These examples from the past two years illustrate the issues of evaluation of expert systems in cybersecurity caused by many specifics of this particular field of application. Evaluation of such and similar tools before 2020 was nearly non‐existent, as noted by Gutzwiller et al 72 …”
Section: Discussionmentioning
confidence: 99%
See 1 more Smart Citation
“…These examples from the past two years illustrate the issues of evaluation of expert systems in cybersecurity caused by many specifics of this particular field of application. Evaluation of such and similar tools before 2020 was nearly non‐existent, as noted by Gutzwiller et al 72 …”
Section: Discussionmentioning
confidence: 99%
“…A testbed could be set up to create a benchmark for the evaluation of the system in a controlled environment. However, field trials and more interactions with potential users shall give more insights than formal evaluation or performance analysis 70‐72 . We plan to extend the number of modeled missions and circle of their stakeholders to collect feedback on the decision support system and its features.…”
Section: Discussionmentioning
confidence: 99%
“…The mean value sequence is subtracted from the original sequence to obtain a new sequence 1 1 () ht with low frequency removed:…”
Section: Empirical Mode Decompositionmentioning
confidence: 99%
“…Various network security threats and complex network attacks mean to make it difficult for traditional anti-virus software, firewalls, and other protective means to take the initiative to defend. To cope with the severe form of network security, the network security situational awareness technology has received extensive attention since it was put forward [1][2] . As its core research category, Through the analysis and fusion of historical network data, the future security of the network can be predicted in advance within a period of time, various threats and attacks that may occur in the future can be warned, network administrators can be helped to allocate network resources reasonably in advance, and corresponding measures can be taken to deal with various network risks.…”
Section: Introductionmentioning
confidence: 99%
“…While allowing for unbiased, objective scored measurements of SA, SAGAT requires a freezing of a simulation for a query response (Endsley et al, 1998). While SAGAT may be leveraged to evaluate a participant's reaction or response to a simulated cyber attack or risk scenario, the digital plane complicates how to measure cyber awareness as data may be collected passively and thus threats may be less overt (Gutzwiller et al, 2020).…”
Section: Measurement Of Cyber Situational Awareness In Clinical Trial...mentioning
confidence: 99%