Frontiers in Psychology | |
Understanding decision making in security operations centres: building the case for cyber deception technology | |
Psychology | |
Debi Ashenden1  Andrew Reeves2  | |
[1] Defence & Security Institute, University of Adelaide, Adelaide, SA, Australia;null; | |
关键词: cyber security; security operation center; deception; active defence; naturalistic decision making; literature review; thematic analysis; | |
DOI : 10.3389/fpsyg.2023.1165705 | |
received in 2023-02-14, accepted in 2023-05-09, 发布年份 2023 | |
来源: Frontiers | |
【 摘 要 】
IntroductionA Security Operations Centre (SOC) is a command centre where analysts monitor network activity, analyse alerts, investigate potential threats, and respond to incidents. By analysing data activities around the clock, SOC teams are crucial in ensuring the prompt detection and response to security incidents. SOC analysts work under considerable pressure to triage and respond to alerts in very short time frames. Cyber deception technology offers the promise of buying SOC analysts more time to respond by wasting the resources and time of attackers, yet such technology remains underutilised.MethodWe carried out a series of interviews with experts to uncover the barriers which prevent the effective implementation of cyber deception in SOCs.ResultsBy using thematic analysis on the data, it was clear that while cyber deception technology is promising it is hindered by a lack of use cases, limited empirical research that demonstrates the efficacy of the technology, hesitancy to embrace a more active form of cyber defence, issues surrounding the over promising of results by off-the-shelf vendors, and an aversion to interrupting the decision-making processes of SOC analysts.DiscussionTaking this last point about the decision-making processes of SOC analysts we make the case that naturalistic decision making (NDM) would help us better understand how SOC analysts make decisions and how cyber deception technology could be used to best effect.
【 授权许可】
Unknown
Copyright © 2023 Reeves and Ashenden.
【 预 览 】
Files | Size | Format | View |
---|---|---|---|
RO202310108164023ZK.pdf | 470KB | download |