Requirements for Playbook-Assisted Cyber Incident Response, Reporting and Automation

被引:0
|
作者
Gurabi, Mehdi Akbari [1 ,2 ]
Nitz, Lasse [1 ,2 ]
Bregar, Andrej [3 ]
Popanda, Jan [1 ]
Siemers, Christian [4 ]
Matzutt, Roman [1 ]
Mandal, Avikarsha [1 ]
机构
[1] Fraunhofer FIT, St Augustin, Germany
[2] Rhein Westfal TH Aachen, Aachen, Germany
[3] Informat Doo, Maribor, Slovenia
[4] Airbus Protect GmbH, Munich, Germany
来源
关键词
Cybersecurity playbooks; response and recovery; machine-readability; THREAT INTELLIGENCE;
D O I
10.1145/3688810
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity playbooks assume an increasingly important role as threat-specific documents for guiding operators in the context of cyber incident response. However, these playbooks are mostly unstructured or semi-structured, which significantly limits their utility when it comes to automating response and reporting steps, complying with cybersecurity directives, or sharing best practices for incident response across organisations. We thus argue that cybersecurity playbooks must transition to interoperable and machine-readable formats from generation, via management and utilisation to cross-organisational sharing. In this work, we identify and structure key requirements based on expert interviews as a first step toward this transition. From these requirements, we derive a framework for further guidance during the transition to structured security playbooks and their utilisation in a tool-assisted fashion. We discuss the implications of our framework and lessons learned before outlining directions for future research.
引用
收藏
页数:11
相关论文
共 50 条
  • [41] Digital Forensics as a Service Implementation: A Scalable Solution for Cyber Incident Response
    Munke, Esho
    Musuva, Paula M. W.
    2024 IST-AFRICA CONFERENCE, 2024,
  • [42] Cyber Resilience and Incident Response in Smart Cities: A Systematic Literature Review
    Ahmadi-Assalemi, Gabriela
    Al-Khateeb, Haider
    Epiphaniou, Gregory
    Maple, Carsten
    SMART CITIES, 2020, 3 (03): : 894 - 927
  • [43] Cyber Threat Intelligence Framework for Incident Response in an Energy Cloud Platform
    Gong, Seonghyeon
    Lee, Changhoon
    ELECTRONICS, 2021, 10 (03) : 1 - 19
  • [44] From Collaboration to Automation: A Proof of Concept tor Improved Incident Response
    Nitz, Lasse
    Zadnik, Martin
    Gurabi, Mehdi Akbari
    Obrecht, Mischa
    Mandal, Avikarsha
    ERCIM NEWS, 2022, (129): : 31 - 32
  • [45] Brace yourself! Why managers should adopt a synthetic media incident response playbook in an age of falsity and synthetic media
    Whittaker, Lucas
    Kietzmann, Jan
    Letheren, Kate
    Mulcahy, Rory
    Russell-Bennett, Rebekah
    BUSINESS HORIZONS, 2023, 66 (02) : 277 - 290
  • [46] Digital Twin-Enhanced Incident Response for Cyber-Physical Systems
    Allison, David
    Smith, Paul
    McLaughlin, Kieran
    18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023, 2023,
  • [47] A Cyber Incident Response and Recovery Framework to Support Operators of Industrial Control Systems
    Staves, Alexander
    Anderson, Tom
    Balderstone, Harry
    Green, Benjamin
    Gouglidis, Antonios
    Hutchison, David
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2022, 37
  • [48] Development of Incident Response Tool for Cyber Security Training Based on Virtualization and Cloud
    Park, Y. S.
    Choi, C. S.
    Jang, C.
    Shin, D. G.
    Cho, G. C.
    Kim, Hwa Soo
    2019 4TH INTERNATIONAL WORKSHOP ON BIG DATA AND INFORMATION SECURITY (IWBIS 2019), 2019, : 115 - 118
  • [49] How integration of cyber security management and incident response enables organizational learning
    Ahmad, Atif
    Desouza, Kevin C.
    Maynard, Sean B.
    Naseer, Humza
    Baskerville, Richard L.
    JOURNAL OF THE ASSOCIATION FOR INFORMATION SCIENCE AND TECHNOLOGY, 2020, 71 (08) : 939 - 953
  • [50] Efficient Incident Response System on Shared Cyber Threat Information Using SDN and STIX
    Okada, Satoshi
    Fujiwara, Yoshiki
    Fujimoto, Mariko
    Matsuda, Wataru
    Mitsunaga, Takuho
    2021 IEEE INTERNATIONAL CONFERENCE ON COMPUTING (ICOCO), 2021, : 109 - 114