Skip to main content

2020 | OriginalPaper | Buchkapitel

Understanding and Enabling Tactical Situational Awareness in a Security Operations Center

verfasst von : Ryan Mullins, Ben Nargi, Adam Fouse

Erschienen in: Advances in Human Factors in Cybersecurity

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Cybersecurity operations are highly complex, requiring the coordination of specialized skills across multiple teams to successfully execute missions. Command and control within security operations centers is dominated by fragile mental models, demonstrating a need for systems that reinforce shared situational awareness across the organization. In this paper, we present the results of our research to: (1) define the needs associated with tactical cyber situational awareness; and (2) evaluate the usability and utility of a prototype tactical situational awareness dashboard. We found that incident tracking, tasking structure, execution timeline, and resource health constitute the essential aspects of tactical cyber situational awareness. Evaluations of prototypes suggest that three visualizations are well suited for conveying this information. We believe these results generalizable and will enable the development of tactical situational awareness capabilities in Security Operations Centers across public and private enterprises.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Endsley, M.R.: Design and evaluation for situation awareness enhancement. In: Proceedings of the Human Factors Society Annual Meeting, vol. 32, no. 2, pp. 97–101. SAGE Publications, Los Angeles (1988) Endsley, M.R.: Design and evaluation for situation awareness enhancement. In: Proceedings of the Human Factors Society Annual Meeting, vol. 32, no. 2, pp. 97–101. SAGE Publications, Los Angeles (1988)
2.
Zurück zum Zitat Franke, U., Brynielsson, J.: Cyber situational awareness–a systematic review of the literature. Comput. Secur. 46, 18–31 (2014)CrossRef Franke, U., Brynielsson, J.: Cyber situational awareness–a systematic review of the literature. Comput. Secur. 46, 18–31 (2014)CrossRef
3.
Zurück zum Zitat Jajodia, S., Noel, S., Kalapa, P., Albanese, M., Williams, J.: Cauldron mission-centric cyber situational awareness with defense in depth. In: MILCOM, pp. 1339–1344 (2011) Jajodia, S., Noel, S., Kalapa, P., Albanese, M., Williams, J.: Cauldron mission-centric cyber situational awareness with defense in depth. In: MILCOM, pp. 1339–1344 (2011)
4.
Zurück zum Zitat Matthews, E.D., Arata III, H.J., Hale, B.L.: Cyber situational awareness. Cyber Def. Rev. 1(1), 35–46 (2016) Matthews, E.D., Arata III, H.J., Hale, B.L.: Cyber situational awareness. Cyber Def. Rev. 1(1), 35–46 (2016)
5.
Zurück zum Zitat Entin, E.E., Serfaty, D.: Adaptive team coordination. Hum. Factors 41(2), 312–325 (1999)CrossRef Entin, E.E., Serfaty, D.: Adaptive team coordination. Hum. Factors 41(2), 312–325 (1999)CrossRef
6.
Zurück zum Zitat MacMillan, J., Entin, E.E., Serfaty, D.: Communication Overhead: The Hidden Cost of Team Cognition. Team Cognition: Process and Performance at the Inter- and Intra-Individual Level. American Psychological Association, Washington, DC (2004) MacMillan, J., Entin, E.E., Serfaty, D.: Communication Overhead: The Hidden Cost of Team Cognition. Team Cognition: Process and Performance at the Inter- and Intra-Individual Level. American Psychological Association, Washington, DC (2004)
7.
Zurück zum Zitat Sundaramurthy, S.C., Case, J., Truong, T., Zomlot, L., Hoffmann, M.: A tale of three security operation centers. In: Proceedings of the 2014 ACM Workshop on Security Information Workers, pp. 43–50. ACM (2014) Sundaramurthy, S.C., Case, J., Truong, T., Zomlot, L., Hoffmann, M.: A tale of three security operation centers. In: Proceedings of the 2014 ACM Workshop on Security Information Workers, pp. 43–50. ACM (2014)
8.
Zurück zum Zitat Cichonski, P., Millar, T., Grance, T., Scarfone, K.: Computer security incident handling guide. NIST Spec. Publ. 800(61), 1–147 (2012) Cichonski, P., Millar, T., Grance, T., Scarfone, K.: Computer security incident handling guide. NIST Spec. Publ. 800(61), 1–147 (2012)
9.
Zurück zum Zitat Cyber Incident Handling Program, CJCSM 6510.01b, Joint Chiefs of Staff, Washington, D.C. (2012) Cyber Incident Handling Program, CJCSM 6510.01b, Joint Chiefs of Staff, Washington, D.C. (2012)
10.
Zurück zum Zitat Shneiderman, B.: The eyes have it: a task by data type taxonomy for information visualizations. In: Proceedings of the 1996 IEEE Symposium on Visual Languages. IEEE (1996) Shneiderman, B.: The eyes have it: a task by data type taxonomy for information visualizations. In: Proceedings of the 1996 IEEE Symposium on Visual Languages. IEEE (1996)
11.
Zurück zum Zitat Halton, J.H.: Algorithm 247: radical-inverse quasi-random point sequence. Commun. ACM 7(12), 701–702 (1964)CrossRef Halton, J.H.: Algorithm 247: radical-inverse quasi-random point sequence. Commun. ACM 7(12), 701–702 (1964)CrossRef
12.
Zurück zum Zitat Bennett, K.B., Flach, J.M.: Display and Interface Design: Subtle Science. Exact Art. CRC Press, Boca Raton (2011)CrossRef Bennett, K.B., Flach, J.M.: Display and Interface Design: Subtle Science. Exact Art. CRC Press, Boca Raton (2011)CrossRef
13.
Zurück zum Zitat Virzi, R.A.: Refining the test phase of usability evaluation: how many subjects is enough? Hum. Factors 34(4), 457–471 (1992)CrossRef Virzi, R.A.: Refining the test phase of usability evaluation: how many subjects is enough? Hum. Factors 34(4), 457–471 (1992)CrossRef
14.
Zurück zum Zitat Woods, D.D.: Essential characteristics of resilience. In: Resilience Engineering, pp. 33–46. CRC Press (2017) Woods, D.D.: Essential characteristics of resilience. In: Resilience Engineering, pp. 33–46. CRC Press (2017)
15.
Zurück zum Zitat Roberts, J.C.: State of the art: coordinated & multiple views in exploratory visualization. In: IEEE Fifth International Conference on Coordinated and Multiple Views in Exploratory Visualization CMV 2007, pp. 61–71 (2007) Roberts, J.C.: State of the art: coordinated & multiple views in exploratory visualization. In: IEEE Fifth International Conference on Coordinated and Multiple Views in Exploratory Visualization CMV 2007, pp. 61–71 (2007)
Metadaten
Titel
Understanding and Enabling Tactical Situational Awareness in a Security Operations Center
verfasst von
Ryan Mullins
Ben Nargi
Adam Fouse
Copyright-Jahr
2020
DOI
https://doi.org/10.1007/978-3-030-52581-1_10

Neuer Inhalt