Modeling Cybersecurity Operations to Improve Resilience

Ivan W. Taylor, Keith D. Willett
{"title":"Modeling Cybersecurity Operations to Improve Resilience","authors":"Ivan W. Taylor,&nbsp;Keith D. Willett","doi":"10.1002/iis2.13132","DOIUrl":null,"url":null,"abstract":"<p>In this paper, we explore the concept of operational resilience of a network or system of computer systems, focusing on the processes of a cybersecurity team within the multi-disciplinary network security operations center. The computer system under examination has faced a cyber-attack that has reduced its capability. The organization's reputation is damaged temporarily but can be restored if the network security operations center can quickly restore the organization's ability to produce desired results. After a cyber-attack, we examine the processes for restoring the system's capability to its original level. These processes will happen sequentially and require close coordination of the cybersecurity team members. We examine a balanced and adaptive assignment policy within the cybersecurity organization to the various processes, showing how these policies can impact the speed with which the system's capability can be restored. Our findings reveal that the adaptive assignment policy among the team members can increase the system restoration rate even though recovering the complete capability of the system may be the same.</p>","PeriodicalId":100663,"journal":{"name":"INCOSE International Symposium","volume":"34 1","pages":"53-71"},"PeriodicalIF":0.0000,"publicationDate":"2024-09-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"INCOSE International Symposium","FirstCategoryId":"1085","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1002/iis2.13132","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

In this paper, we explore the concept of operational resilience of a network or system of computer systems, focusing on the processes of a cybersecurity team within the multi-disciplinary network security operations center. The computer system under examination has faced a cyber-attack that has reduced its capability. The organization's reputation is damaged temporarily but can be restored if the network security operations center can quickly restore the organization's ability to produce desired results. After a cyber-attack, we examine the processes for restoring the system's capability to its original level. These processes will happen sequentially and require close coordination of the cybersecurity team members. We examine a balanced and adaptive assignment policy within the cybersecurity organization to the various processes, showing how these policies can impact the speed with which the system's capability can be restored. Our findings reveal that the adaptive assignment policy among the team members can increase the system restoration rate even though recovering the complete capability of the system may be the same.

建立网络安全操作模型以提高复原力
在本文中,我们探讨了计算机系统网络或系统的运行复原力概念,重点是多学科网络安全运行中心内网络安全团队的流程。所研究的计算机系统曾遭遇网络攻击,导致其能力下降。该组织的声誉暂时受损,但如果网络安全运营中心能迅速恢复该组织的能力,就能达到预期效果。网络攻击发生后,我们要检查将系统能力恢复到原有水平的流程。这些过程将按顺序进行,需要网络安全团队成员的密切配合。我们研究了网络安全组织内部对各个流程的平衡和自适应分配政策,展示了这些政策如何影响系统能力的恢复速度。我们的研究结果表明,团队成员之间的自适应分配政策可以提高系统恢复速度,即使恢复系统的完整能力可能是相同的。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信