Formalizing and Integrating User Knowledge into Security Analytics

被引:0
|
作者
Böhm F. [1 ]
Vielberth M. [1 ]
Pernul G. [1 ]
机构
[1] Chair of Information Systems, University of Regensburg, Universitätstr. 31, Bavaria, Regensburg
关键词
Domain knowledge; Security analytics; Security awareness; Security operations; Visual analytics;
D O I
10.1007/s42979-022-01209-7
中图分类号
学科分类号
摘要
The Internet-of-Things and ubiquitous cyber-physical systems increase the attack surface for cyber-physical attacks. They exploit technical vulnerabilities and human weaknesses to wreak havoc on organizations’ information systems, physical machines, or even humans. Taking a stand against these multi-dimensional attacks requires automated measures to be combined with people as their knowledge has proven critical for security analytics. However, there is no uniform understanding of information security knowledge and its integration into security analytics activities. With this work, we structure and formalize the crucial notions of knowledge that we deem essential for holistic security analytics. A corresponding knowledge model is established based on the Incident Detection Lifecycle, which summarizes the security analytics activities. This idea of knowledge-based security analytics highlights a dichotomy in security analytics. Security experts can operate security mechanisms and thus contribute their knowledge. However, security novices often cannot operate security mechanisms and, therefore, cannot make their highly-specialized domain knowledge available for security analytics. This results in several severe knowledge gaps. We present a research prototype that shows how several of these knowledge gaps can be overcome by simplifying the interaction with automated security analytics techniques. © 2022, The Author(s).
引用
收藏
相关论文
共 50 条
  • [1] User and Entity Behavior Analytics for Enterprise Security
    Shashanka, Madhu
    Shen, Min-Yi
    Wang, Jisheng
    2016 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2016, : 1867 - 1874
  • [2] Bridging Knowledge Gaps in Security Analytics
    Boehm, Fabian
    Vielberth, Manfred
    Pernul, Guenther
    ICISSP: PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2021, : 98 - 108
  • [3] Framework of Data Analytics and Integrating Knowledge Management
    Schaefer C.
    Makatsaria A.
    International Journal of Intelligent Networks, 2021, 2 : 156 - 165
  • [4] Security Analytics: Essential Data Analytics Knowledge for Cybersecurity Professionals and Students
    Verma, Rakesh
    Kantarcioglu, Murat
    Marchette, David
    Leiss, Ernst
    Solorio, Thamar
    IEEE SECURITY & PRIVACY, 2015, 13 (06) : 60 - 65
  • [5] Formalizing analytical discourse in visual analytics
    Cai, Guoray
    VAST: IEEE SYMPOSIUM ON VISUAL ANALYTICS SCIENCE AND TECHNOLOGY 2007, PROCEEDINGS, 2007, : 217 - 218
  • [6] Formalizing user actions for ontologies
    Soon, K
    Kuhn, W
    GEOGRAPHIC INFORMATION SCIENCE, PROCEEDINGS, 2004, 3234 : 299 - 312
  • [7] Integrating Heterogeneous Security Knowledge Sources for Comprehensive Security Analysis
    Wang, Guodi
    Li, Tong
    Yue, Hao
    Yang, Zhen
    Zhang, Runzi
    2021 IEEE 45TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2021), 2021, : 714 - 724
  • [8] Integrating Modeling Languages and Web Logs for Enhanced User Behavior Analytics
    Bernaschina, Carlo
    Brambilla, Marco
    Koka, Thanas
    Mauri, Andrea
    Umuhoza, Eric
    WWW'17 COMPANION: PROCEEDINGS OF THE 26TH INTERNATIONAL CONFERENCE ON WORLD WIDE WEB, 2017, : 171 - 175
  • [9] User-Profile-Based Analytics for Detecting Cloud Security Breaches
    Tiwari, Trishita
    Turk, Ata
    Oprea, Alina
    Olcoz, Katzalin
    Coskun, Ayse K.
    2017 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2017, : 4529 - 4535
  • [10] Integrating User Feedback with Heuristic Security and Privacy Management Systems
    Ayyavu, Prashanth
    Jensen, Carlos
    29TH ANNUAL CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, 2011, : 2305 - 2314