Requirements for Playbook-Assisted Cyber Incident Response, Reporting and Automation

被引:0
|
作者
Gurabi, Mehdi Akbari [1 ,2 ]
Nitz, Lasse [1 ,2 ]
Bregar, Andrej [3 ]
Popanda, Jan [1 ]
Siemers, Christian [4 ]
Matzutt, Roman [1 ]
Mandal, Avikarsha [1 ]
机构
[1] Fraunhofer FIT, St Augustin, Germany
[2] Rhein Westfal TH Aachen, Aachen, Germany
[3] Informat Doo, Maribor, Slovenia
[4] Airbus Protect GmbH, Munich, Germany
来源
关键词
Cybersecurity playbooks; response and recovery; machine-readability; THREAT INTELLIGENCE;
D O I
10.1145/3688810
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity playbooks assume an increasingly important role as threat-specific documents for guiding operators in the context of cyber incident response. However, these playbooks are mostly unstructured or semi-structured, which significantly limits their utility when it comes to automating response and reporting steps, complying with cybersecurity directives, or sharing best practices for incident response across organisations. We thus argue that cybersecurity playbooks must transition to interoperable and machine-readable formats from generation, via management and utilisation to cross-organisational sharing. In this work, we identify and structure key requirements based on expert interviews as a first step toward this transition. From these requirements, we derive a framework for further guidance during the transition to structured security playbooks and their utilisation in a tool-assisted fashion. We discuss the implications of our framework and lessons learned before outlining directions for future research.
引用
收藏
页数:11
相关论文
共 50 条
  • [22] Actionable Cyber Threat Intelligence for Automated Incident Response
    Leite, Cristoffer
    den Hartog, Jerry
    dos Santos, Daniel Ricardo
    Costante, Elisa
    SECURE IT SYSTEMS, NORDSEC 2022, 2022, 13700 : 368 - 385
  • [23] Unpacking Russia's Cyber-Incident Response
    Kolodii, Roman
    SECURITY STUDIES, 2024,
  • [24] European framework and proofs-of-concept for the intelliGent aUtomAtion of cybeR Defence Incident mAnagemeNt
    Garcia Cid, Marta Irene
    Gil Perez, Manuel
    Jorquera Valero, Jose Maria
    Lopez Martinez, Antonio
    Maestre Vidal, Jorge
    Martinez Perez, Gregorio
    Mendez Garcia, Laura
    Munoz Plaza, Frida
    Nespoli, Pantaleone
    Pastor Galindo, Javier
    Ramon y Cajal Ramo, Pedro Jose
    Rodriguez Lopez, Francisco Antonio
    Sanchez Sanchez, Pedro Miguel
    Sotelo Monge, Marco Antonio
    2023 JNIC CYBERSECURITY CONFERENCE, JNIC, 2023,
  • [25] Cyber Incident Response Aided by Neural Networks and Visual Analytics
    Mihai-Gabriel, Ionita
    Victor-Valeriu, Patriciu
    2015 20TH INTERNATIONAL CONFERENCE ON CONTROL SYSTEMS AND COMPUTER SCIENCE, 2015, : 229 - 233
  • [26] Differentiating the Investigation Response Process of Cyber Security Incident for LEAs
    Hsiao, Shou-Ching
    Kao, Da-Yu
    INTELLIGENCE AND SECURITY INFORMATICS (PAISI 2017), 2017, 10241 : 34 - 48
  • [27] Operation Raven Design of a Cyber Security Incident Response Game
    Seiler, Andreas
    Lechner, Ulrike
    Strussenberg, Judith
    Hofbauer, Stefan
    INNOVATIONS FOR COMMUNITY SERVICES, I4CS 2024, 2024, 2109 : 337 - 347
  • [28] Jack pandemus - Cyber incident and emergency response during a pandemic
    Korn, Erik B.
    Fletcher, Douglas M.
    Mitchell, Erica M.
    Pyke, Aryn A.
    Whitham, Steven M.
    INFORMATION SECURITY JOURNAL, 2021, 30 (05): : 294 - 307
  • [29] Informing Hybrid System Design in Cyber Security Incident Response
    Nyre-Yu, Megan
    Sprehn, Kelly A.
    Caldwell, Barrett S.
    HCI FOR CYBERSECURITY, PRIVACY AND TRUST, 2019, 11594 : 325 - 338
  • [30] Towards Incident Response Orchestration and Automation for the Advanced Metering Infrastructure
    Lekidis, Alexios
    Mavroeidis, Vasileios
    Fysarakis, Konstantinos
    2024 IEEE 20TH INTERNATIONAL CONFERENCE ON FACTORY COMMUNICATION SYSTEMS, WFCS, 2024, : 103 - 110