ARIMA Supplemented Security Metrics for Quality Assurance and Situational Awareness

被引:3
|
作者
Kohlrausch, Jan [1 ]
Brin, Eugene A. [1 ]
机构
[1] DFN CERT, Nagelsweg 41, Hamburg, Germany
来源
基金
欧盟地平线“2020”;
关键词
ARIMA supplemented metrics; CSIRT services; threat intelligence; situational awareness; quality control; ARIMA; prediction based anomaly detection; time series analysis; SCIENCE; DESIGN;
D O I
10.1145/3376926
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Quality assurance and situational awareness are important areas of interest for CSIRTs and security teams. Significant efforts have been made on defining metrics measuring critical parameters for these fields of application. However, methodical approaches are missing or lacking precision to enable a reliable usage of such metrics for quality assurance and situational awareness. In this contribution, we introduce a method that generalizes the application of ARIMA time series analysis on a well-defined set of metrics (ARIMA supplemented metrics) to facilitate and support quality assurance and situational awareness services. This method is based on research on ARIMA models and metrics and builds on CSIRT best practices. We show how data analysts and security practitioners can incorporate this method into existing best practices for CSIRT services pertaining to quality assurance and situational awareness. The applicability of this method is demonstrated by integrating ARIMA supplemented metrics into exemplary processes for quality assurance and situational awareness to support data analysts and security practitioners in CSIRTs and security teams.
引用
收藏
页数:21
相关论文
共 50 条
  • [41] Application of Cyber Situational Awareness and Cyber Security in Vehicular Networks
    Eiza, Mahmoud Hashem
    2017 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA), 2017,
  • [42] A Hierarchical Architectural Model for Network Security Exploring Situational Awareness
    Almeida, Ricardo Borges
    Covalski, Victor
    Machado, Roger
    Leal da Rosa, Diorgenes Yuri
    Yamin, Adenauer Correa
    Donato, Lucas Medeiros
    Pernas, Ana Marilza
    SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING, 2019, : 1365 - 1372
  • [43] A novel stochastic modeling method for network security situational awareness
    Liang, Y.
    Wang, H. Q.
    Cai, H. B.
    He, Y. J.
    ICIEA 2008: 3RD IEEE CONFERENCE ON INDUSTRIAL ELECTRONICS AND APPLICATIONS, PROCEEDINGS, VOLS 1-3, 2008, : 2422 - +
  • [44] The Information System Security Situational Awareness Based On Cloud Computing
    Ma Zhicheng
    Jin Lin
    Yang Peng
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND SERVICE SYSTEM (CSSS), 2014, 109 : 583 - 586
  • [45] Network video image processing for security, surveillance, and situational awareness
    Mahalanobis, A
    Cannon, J
    Stanfill, SR
    Muise, R
    Martin, L
    Shah, M
    DIGITAL WIRELESS COMMUNICATIONS VI, 2004, 5440 : 1 - 8
  • [46] Trusted network security situational awareness and forecast based on SPA
    Wu, Kun
    Bai, Zhong-Ying
    Harbin Gongye Daxue Xuebao/Journal of Harbin Institute of Technology, 2012, 44 (03): : 112 - 118
  • [47] Application of Cyber Situational Awareness and Cyber Security in Vehicular Networks
    Eiza, Mahmoud Hashem
    2017 INTERNATIONAL CONFERENCE ON CYBER SECURITY AND PROTECTION OF DIGITAL SERVICES (CYBER SECURITY), 2017,
  • [48] Network security situational awareness model based on threat intelligence
    Zhang H.
    Yin Y.
    Zhao D.
    Liu B.
    1600, Editorial Board of Journal on Communications (42): : 182 - 194
  • [49] A Network Security Situational Awareness Model Based on Information Fusion
    Abasi
    ADVANCES IN MECHATRONICS, AUTOMATION AND APPLIED INFORMATION TECHNOLOGIES, PTS 1 AND 2, 2014, 846-847 : 1632 - 1635
  • [50] Comprehensive analysis of Network security situational awareness methods and models
    Wei, Xiumei
    Jiang, Xuesong
    2013 2ND INTERNATIONAL SYMPOSIUM ON INSTRUMENTATION AND MEASUREMENT, SENSOR NETWORK AND AUTOMATION (IMSNA), 2013, : 176 - 179