ARIMA Supplemented Security Metrics for Quality Assurance and Situational Awareness

被引:3
|
作者
Kohlrausch, Jan [1 ]
Brin, Eugene A. [1 ]
机构
[1] DFN CERT, Nagelsweg 41, Hamburg, Germany
来源
基金
欧盟地平线“2020”;
关键词
ARIMA supplemented metrics; CSIRT services; threat intelligence; situational awareness; quality control; ARIMA; prediction based anomaly detection; time series analysis; SCIENCE; DESIGN;
D O I
10.1145/3376926
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Quality assurance and situational awareness are important areas of interest for CSIRTs and security teams. Significant efforts have been made on defining metrics measuring critical parameters for these fields of application. However, methodical approaches are missing or lacking precision to enable a reliable usage of such metrics for quality assurance and situational awareness. In this contribution, we introduce a method that generalizes the application of ARIMA time series analysis on a well-defined set of metrics (ARIMA supplemented metrics) to facilitate and support quality assurance and situational awareness services. This method is based on research on ARIMA models and metrics and builds on CSIRT best practices. We show how data analysts and security practitioners can incorporate this method into existing best practices for CSIRT services pertaining to quality assurance and situational awareness. The applicability of this method is demonstrated by integrating ARIMA supplemented metrics into exemplary processes for quality assurance and situational awareness to support data analysts and security practitioners in CSIRTs and security teams.
引用
收藏
页数:21
相关论文
共 50 条
  • [21] Metrics on the space of bounded Keplerian orbits and space situational awareness
    Maruskin, Jared M.
    Scheeres, Daniel J.
    PROCEEDINGS OF THE 48TH IEEE CONFERENCE ON DECISION AND CONTROL, 2009 HELD JOINTLY WITH THE 2009 28TH CHINESE CONTROL CONFERENCE (CDC/CCC 2009), 2009, : 5912 - 5917
  • [22] Quality Assurance Metrics for MANET Evaluation
    Kush, Ashwani
    2014 3RD INTERNATIONAL CONFERENCE ON RELIABILITY, INFOCOM TECHNOLOGIES AND OPTIMIZATION (ICRITO) (TRENDS AND FUTURE DIRECTIONS), 2014,
  • [23] An Ontological Approach to Situational Awareness Applied to Information Security
    da Rosa, Diorgenes Yuri
    Almeida, Ricardo
    Machado, Roger
    Yamin, Adenauer
    Pernas, Ana Marilza
    2018 XLIV LATIN AMERICAN COMPUTER CONFERENCE (CLEI 2018), 2018, : 718 - 727
  • [24] Application of Crawler Algorithm for Situational Awareness in Network Security
    Jagadish, Sripelli
    Madanan, Mukesh
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON DATA SCIENCE, MACHINE LEARNING AND APPLICATIONS, VOL 1, ICDSMLA 2023, 2025, 1273 : 429 - 438
  • [25] Research on Host-Level Security Situational Awareness
    Zhou Ti
    Wang Xiao-fei
    Feng Li
    Wang Jing
    PROCEEDINGS 2010 3RD IEEE INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY, (ICCSIT 2010), VOL 1, 2010, : 575 - 579
  • [26] Shared Situational Awareness in Information Security Incident Management
    Padayachee, Keshnee
    Worku, Elias
    2017 12TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2017, : 479 - 483
  • [27] A Study of Network Security Situational Awareness in Internet of Things
    Li, Jingyi
    Yi, Xiaoyin
    Wei, Shi
    2020 16TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE, IWCMC, 2020, : 1624 - 1629
  • [28] Improved Information Security Situational Awareness by Manifold Visualisation
    Evesti, Antti
    Wieser, Christian
    Zhao, Tiandu
    ACM PROCEEDINGS OF THE 10TH EUROPEAN CONFERENCE ON SOFTWARE ARCHITECTURE WORKSHOPS (ECSA-W), 2016,
  • [29] Sensing the Arctic: Situational awareness and the future of northern security
    Johnson, Benjamin T.
    INTERNATIONAL JOURNAL, 2021, 76 (03): : 404 - 426
  • [30] Functional Requirements of Situational Awareness in Computer Network Security
    Onwubiko, Cyril
    ISI: 2009 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS, 2009, : 209 - 213