Approaches to Improve the Activity of Computer Incident Response Teams

被引:0
|
作者
Gizun, Andrii [1 ]
Gnatyuk, Viktor [1 ]
Balyk, Nadiia [2 ]
Falat, Pawel [2 ]
机构
[1] Natl Aviat Univ, 1 Kosmonavta Komarova Ave, UA-03680 Kiev, Ukraine
[2] Univ Bielsko Biala, PL-43309 Bielsko Biala, Poland
关键词
incident; computer incident response teams (CERT); approaches to ensure efficiency; parameters; problem of incident detection; fuzzy conditions;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Today incident detection mechanisms, that define CERT / CSIRT effectiveness, based mostly on two principles - signature and heuristic. Their disadvantage is that they are focused on mathematical models, which require a lot of time to prepare statistics and so it decreases CERT/CSIRT efficiency. In this work, we have proposed approaches to ensure CERT / CSIRT high efficiency and its evaluation. To detect incidents we suggest using mathematical models based on expert's estimations. The proposed method allows solving the problem of incident detection and its identification based on expert judgments in fuzzy conditions. To estimate CERT / CSIRT effectiveness was introduce baselines. It enabled to determine CERT / CSIRT effectiveness during the necessary period. The report by the following parameters should be carried out regularly to get the full picture of their changes and identify the main trend.
引用
收藏
页码:442 / 447
页数:6
相关论文
共 50 条
  • [1] On Computer Security Incident Response Teams
    Horne, Bill
    IEEE SECURITY & PRIVACY, 2014, 12 (05) : 13 - 15
  • [2] Methodology for Computer Security Incident Response Teams into IoT Strategy
    Enciso Bernal, Alejandro
    Martinez Monterrubio, Sergio Mauricio
    Parra Puente, Javier
    Gonzalez Crespo, Ruben
    Verdu, Elena
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2021, 15 (05): : 1909 - 1928
  • [3] An Organizational Psychology Perspective to Examining Computer Security Incident Response Teams
    Chen, Tiffani R.
    Shore, Daniel B.
    Zaccaro, Stephen J.
    Dalal, Reeshad S.
    Tetrick, Lois E.
    Gorab, Aiva K.
    IEEE SECURITY & PRIVACY, 2014, 12 (05) : 61 - 67
  • [4] Services Establishment in the Computer Security Incident Response Teams: A Review of State of Art
    Jezreel, Mejia
    Mirna, Munoz
    Edgar, Uribe
    2015 10TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI), 2015,
  • [5] Measuring Expert and Novice Performance Within Computer Security Incident Response Teams
    Silva, Austin
    Emmanuel, Glory
    McClain, Jonathan T.
    Matzen, Laura
    Forsythe, Chris
    FOUNDATIONS OF AUGMENTED COGNITION, AC 2015, 2015, 9183 : 144 - 152
  • [6] Computer security incident response teams: are they legally regulated? The Swiss exampleComputer Security Incident Response Teams: Sind sie gesetzlich geregelt? Das Schweizer Beispiel
    Pauline Meyer
    Sylvain Métille
    International Cybersecurity Law Review, 2023, 4 (1): : 39 - 60
  • [7] Incident response teams need to change
    Schultz, E
    COMPUTERS & SECURITY, 2004, 23 (02) : 87 - 88
  • [8] USER APPROACHES TO COMPUTER-SUPPORTED TEAMS
    JOHANSEN, R
    TECHNOLOGICAL SUPPORT FOR WORK GROUP COLLABORATION, 1989, : 1 - 31
  • [9] Rapid response teams improve outcomes: no
    Maharaj, Ritesh
    Stelfox, Henry T.
    INTENSIVE CARE MEDICINE, 2016, 42 (04) : 596 - 598
  • [10] Rapid response teams improve outcomes: no
    Ritesh Maharaj
    Henry T. Stelfox
    Intensive Care Medicine, 2016, 42 : 596 - 598