2021
DOI: 10.1145/3430753
|View full text |Cite
|
Sign up to set email alerts
|

Assessing a Decision Support Tool for SOC Analysts

Abstract: In recent years, many tools have been developed to understand attacks that make use of visualization, but few examples aims to predict real-world consequences. We have developed a visualization tool that aims to improve decision support during attacks. Our tool visualizes propagation of risks from IDS and AV-alert data by relating sensor alerts to Business Process (BP) tasks and machine assets: an important capability gap present in many Security Operation Centres (SOCs) today. In this paper we present a user … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
7
0

Year Published

2021
2021
2023
2023

Publication Types

Select...
4
2

Relationship

0
6

Authors

Journals

citations
Cited by 7 publications
(7 citation statements)
references
References 23 publications
0
7
0
Order By: Relevance
“…The preliminary steps towards evaluating such systems were investigated very recently, for example, in the work of Rodriguez‐Bermejo et al, 70 who propose an evaluation methodology for mission‐centric cyber situational awareness capabilities covering correct technical implementation, core functionality, and user acceptance. In another example, Happa et al 71 conducted a user evaluation study of decision support tools for SOC analysts. A recent complex decision support system for cybersecurity incident handling proposed by Husák et al 2 also resorted to case study and user evaluation.…”
Section: Discussionmentioning
confidence: 99%
See 2 more Smart Citations
“…The preliminary steps towards evaluating such systems were investigated very recently, for example, in the work of Rodriguez‐Bermejo et al, 70 who propose an evaluation methodology for mission‐centric cyber situational awareness capabilities covering correct technical implementation, core functionality, and user acceptance. In another example, Happa et al 71 conducted a user evaluation study of decision support tools for SOC analysts. A recent complex decision support system for cybersecurity incident handling proposed by Husák et al 2 also resorted to case study and user evaluation.…”
Section: Discussionmentioning
confidence: 99%
“…A testbed could be set up to create a benchmark for the evaluation of the system in a controlled environment. However, field trials and more interactions with potential users shall give more insights than formal evaluation or performance analysis 70‐72 . We plan to extend the number of modeled missions and circle of their stakeholders to collect feedback on the decision support system and its features.…”
Section: Discussionmentioning
confidence: 99%
See 1 more Smart Citation
“…Further exploring the tacit aspects of decision making occurring within contemporary SOCs, Happa et al (2021) evaluate the effectiveness of a decision support tool for SOC analysts. The authors conduct a user study to assess the tool’s ability to support analysts in decision-making, triage, and prioritization tasks.…”
Section: Literature Reviewmentioning
confidence: 99%
“…Recently, recommender systems were employed for the cybersecurity needs to help address the cyber attacks at the right place at the right time [3], [7], [8]. However, the cybersecurity teams are often understaffed or overloaded with work to successfully deploy all the tools proposed in recent research, namely in situations when the tools require non-trivial amounts of high-quality data or other inputs that are hard to collect [6], [9].…”
Section: Introductionmentioning
confidence: 99%