Human-centered Assessment of Automated Tools for Improved Cyber Situational Awareness

被引:0
|
作者
Strickson, Benjamin [1 ]
Worsley, Cameron [1 ]
Bertram, Stewart [1 ]
机构
[1] Elemendar, London, England
关键词
human-centered AI; cyber situational awareness; autonomous capabilities;
D O I
10.23919/CYCON58705.2023.10181567
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Attempts to deploy autonomous capabilities, including artificial intelligence (AI), within cybersecurity workflows have been met with an implementation challenge. Often the impediment is the ability of software engineers to assess and quantify the benefits of machine learning (ML) models for cyber analysts. We present a case study demonstrating the successful testing and improvement of an ML tool through human-centered assessments. For the benefit of researchers in this field, we detail our own wargaming environment, which was tested using members of a government intelligence community. The participants were presented with two cybersecurity tasks: report annotation and a situational awareness assessment. Both of these tasks were statistically assessed for the difference between task completion with and without access to automation tools. Our first experiment - report annotation - showed a task improvement of +14.0 ppts in recall and +9.19 ppts in precision; there was an overall significant positive difference in f1 values for the ML subjects (p < 0.01). Our second experiment - cyber situational awareness (CSA) - showed a 66.7% improvement in user scores and a significant positive difference for the ML subjects (p < 0.01). The conclusions of our work focus on the need to rebalance the attention of software engineers away from quantitative metrics and toward qualitative analyst feedback derived from realistic wargame testing frameworks. We believe that sharing our wargame scenario here will allow other organizations to either adopt the same testing methodology or, alternatively, share their own CSA testing framework. Ultimately, we are hoping for a more open dialogue between researchers working across the cyber industry and government intelligence agencies.
引用
收藏
页码:273 / 286
页数:14
相关论文
共 50 条
  • [1] Framework for risk assessment in cyber situational awareness
    Xi Rongrong
    Yun Xiaochun
    Hao Zhiyu
    [J]. IET INFORMATION SECURITY, 2019, 13 (02) : 149 - 156
  • [2] Human-Centered Automated Proof Search
    Wilfried Sieg
    Farzaneh Derakhshan
    [J]. Journal of Automated Reasoning, 2021, 65 : 1153 - 1190
  • [3] Human-Centered Design in an Automated World
    Blackett, Claire
    [J]. INTELLIGENT HUMAN SYSTEMS INTEGRATION 2021, 2021, 1322 : 17 - 23
  • [4] Human-Centered Automated Proof Search
    Sieg, Wilfried
    Derakhshan, Farzaneh
    [J]. Journal of Automated Reasoning, 2021, 65 (08): : 1153 - 1190
  • [5] Human-Centered Automated Proof Search
    Sieg, Wilfried
    Derakhshan, Farzaneh
    [J]. JOURNAL OF AUTOMATED REASONING, 2021, 65 (08) : 1153 - 1190
  • [6] Human Centered Cyber Situation Awareness
    Mancuso, Vincent
    McGuire, Sarah
    Staheli, Diane
    [J]. ADVANCES IN HUMAN FACTORS IN CYBERSECURITY, 2020, 960 : 69 - 78
  • [7] Human-Centered Interfaces for Situation Awareness in Maintenance
    Oliveira, Allan
    Araujo, Regina
    Jardine, Andrew
    [J]. HUMAN INTERFACE AND THE MANAGEMENT OF INFORMATION: INFORMATION AND KNOWLEDGE IN APPLICATIONS AND SERVICES, PT II, 2014, 8522 : 193 - 204
  • [8] Human-Centered Risk Assessment of an Automated Vehicle Using Vehicular Wireless Communication
    Shin, Donghoon
    Kim, Beomjun
    Yi, Kyongsu
    Carvalho, Ashwin
    Borrelli, Francesco
    [J]. IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2019, 20 (02) : 667 - 681
  • [9] Enhancing Cyber Situational Awareness: A New Perspective of Password Auditing Tools
    Stavrou, Eliana
    [J]. 2018 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA), 2018,
  • [10] Tools and Techniques for Improving Cyber Situational Awareness of Targeted Phishing Attacks
    Legg, Phil
    Blackman, Tim
    [J]. 2019 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA), 2019,