ARIMA Supplemented Security Metrics for Quality Assurance and Situational Awareness

被引:3
|
作者
Kohlrausch, Jan [1 ]
Brin, Eugene A. [1 ]
机构
[1] DFN CERT, Nagelsweg 41, Hamburg, Germany
来源
基金
欧盟地平线“2020”;
关键词
ARIMA supplemented metrics; CSIRT services; threat intelligence; situational awareness; quality control; ARIMA; prediction based anomaly detection; time series analysis; SCIENCE; DESIGN;
D O I
10.1145/3376926
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Quality assurance and situational awareness are important areas of interest for CSIRTs and security teams. Significant efforts have been made on defining metrics measuring critical parameters for these fields of application. However, methodical approaches are missing or lacking precision to enable a reliable usage of such metrics for quality assurance and situational awareness. In this contribution, we introduce a method that generalizes the application of ARIMA time series analysis on a well-defined set of metrics (ARIMA supplemented metrics) to facilitate and support quality assurance and situational awareness services. This method is based on research on ARIMA models and metrics and builds on CSIRT best practices. We show how data analysts and security practitioners can incorporate this method into existing best practices for CSIRT services pertaining to quality assurance and situational awareness. The applicability of this method is demonstrated by integrating ARIMA supplemented metrics into exemplary processes for quality assurance and situational awareness to support data analysts and security practitioners in CSIRTs and security teams.
引用
收藏
页数:21
相关论文
共 50 条
  • [1] ARIMA Security Metrics: Facilitating Decision-making Processes and Situational Awareness in Threat Intelligence
    Kohlrausch, Jan
    ERCIM NEWS, 2022, (129): : 30 - 31
  • [2] Taxonomy of quality metrics for assessing assurance of security correctness
    Ouedraogo, Moussa
    Savola, Reijo M.
    Mouratidis, Haralambos
    Preston, David
    Khadraoui, Djamel
    Dubois, Eric
    SOFTWARE QUALITY JOURNAL, 2013, 21 (01) : 67 - 97
  • [3] Taxonomy of quality metrics for assessing assurance of security correctness
    Moussa Ouedraogo
    Reijo M. Savola
    Haralambos Mouratidis
    David Preston
    Djamel Khadraoui
    Eric Dubois
    Software Quality Journal, 2013, 21 : 67 - 97
  • [4] Using Security Metrics in Software Quality Assurance Process
    Abdi, Athena
    Souzani, Afshin
    Amirfakhri, Maliheh
    Moghadam, Azadeh Bamdad
    2012 SIXTH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST), 2012, : 1099 - 1102
  • [5] Interactive Analysis of Situational Awareness Metrics
    Overby, Derek
    Wall, Jim
    Keyser, John
    VISUALIZATION AND DATA ANALYSIS 2012, 2012, 8294
  • [6] Security and Business Situational Awareness
    Rieke, Roland
    Zhdanova, Maria
    Repp, Juergen
    CYBER SECURITY AND PRIVACY, CSP INNOVATION FORUM 2015, 2015, 530 : 103 - 115
  • [7] Cyber Security Situational Awareness
    Tianfield, Huaglory
    2016 IEEE INTERNATIONAL CONFERENCE ON INTERNET OF THINGS (ITHINGS) AND IEEE GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) AND IEEE CYBER, PHYSICAL AND SOCIAL COMPUTING (CPSCOM) AND IEEE SMART DATA (SMARTDATA), 2016, : 782 - 787
  • [8] "Being Aware!" - Situational Awareness and Its Importance in Safety and Quality Assurance in Neurosurgery
    Sarkar, Hrishikesh
    NEUROLOGY INDIA, 2020, 68 (05) : 1166 - 1169
  • [9] Metrics for Situational awareness using sensor networks
    Crespi, V
    Cybenko, G
    SENSORS, AND COMMAND, CONTROL, COMMUNICATIONS, AND INTELLIGENCE (C31) TECHNOLOGIES FOR HOMELAND SECURITY AND HOMELAND DEFENSE IV, PTS 1 AND 2, 2005, 5778 : 934 - 944
  • [10] Survey of Network Security Situational Awareness
    Yao, Jiayu
    Fan, Xiani
    Cao, Ning
    CYBERSPACE SAFETY AND SECURITY, PT I, 2020, 11982 : 34 - 44