网络防御分析人员网络认知态势感知特征的任务分析

R. Gutzwiller, Sarah M. Hunt, D. Lange
{"title":"网络防御分析人员网络认知态势感知特征的任务分析","authors":"R. Gutzwiller, Sarah M. Hunt, D. Lange","doi":"10.1109/COGSIMA.2016.7497780","DOIUrl":null,"url":null,"abstract":"Cyberspace is an increasingly crucial part of everyday living. We have long recognized that defending this space is complex, requiring information integration, and decisions of man and machine to coalesce in a dynamic environment full of shifting priorities. These properties suggest that, as in other domains with similar characteristics, situation awareness (SA) of a human cyber defender is paramount to the quality of decision outcomes in cyber defense. The majority of existing research in cyber situation awareness, centers on information systems and computers, which piece together disparate data. Fused data from multiple sources, for example, is necessary for cyberspace visualization efforts. The judgment for successful cyber SA from this perspective is different from one that is human-centered. In comparison, we rarely assess human cognitive awareness in cyberspace. In part, this reflects a need, based on prior theory, to first define critical elements of information that the human must perceive, work to elucidate how humans combine these elements to comprehend the state of the network, and how together, this awareness helps analysts predict the future state of the network. In other words, although data fusion can provide value by reducing the cognitive load created to piece together disparate sources of information, human awareness of the network (cyber-cognitive situation awareness - CCSA) is perhaps the ultimate intermediary for defense performance. Toward such an understanding, we discuss the results of a cognitive task analysis (CTA) which sought to determine the goals and abstracted elements of awareness that cyber analysts seek in network defense. We present the foundation for a series of planned experiments that establishes CCSA measurement, and baselines the efforts of cyber defenders. Once assessed, we can then begin to consider the help offered by fusion systems, automation of defensive capabilities, and cyber visualizations in a methodologically rigorous manner that has been lacking.","PeriodicalId":194697,"journal":{"name":"2016 IEEE International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision Support (CogSIMA)","volume":"199 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-03-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"45","resultStr":"{\"title\":\"A task analysis toward characterizing cyber-cognitive situation awareness (CCSA) in cyber defense analysts\",\"authors\":\"R. Gutzwiller, Sarah M. Hunt, D. Lange\",\"doi\":\"10.1109/COGSIMA.2016.7497780\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Cyberspace is an increasingly crucial part of everyday living. We have long recognized that defending this space is complex, requiring information integration, and decisions of man and machine to coalesce in a dynamic environment full of shifting priorities. These properties suggest that, as in other domains with similar characteristics, situation awareness (SA) of a human cyber defender is paramount to the quality of decision outcomes in cyber defense. The majority of existing research in cyber situation awareness, centers on information systems and computers, which piece together disparate data. Fused data from multiple sources, for example, is necessary for cyberspace visualization efforts. The judgment for successful cyber SA from this perspective is different from one that is human-centered. In comparison, we rarely assess human cognitive awareness in cyberspace. In part, this reflects a need, based on prior theory, to first define critical elements of information that the human must perceive, work to elucidate how humans combine these elements to comprehend the state of the network, and how together, this awareness helps analysts predict the future state of the network. In other words, although data fusion can provide value by reducing the cognitive load created to piece together disparate sources of information, human awareness of the network (cyber-cognitive situation awareness - CCSA) is perhaps the ultimate intermediary for defense performance. Toward such an understanding, we discuss the results of a cognitive task analysis (CTA) which sought to determine the goals and abstracted elements of awareness that cyber analysts seek in network defense. We present the foundation for a series of planned experiments that establishes CCSA measurement, and baselines the efforts of cyber defenders. Once assessed, we can then begin to consider the help offered by fusion systems, automation of defensive capabilities, and cyber visualizations in a methodologically rigorous manner that has been lacking.\",\"PeriodicalId\":194697,\"journal\":{\"name\":\"2016 IEEE International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision Support (CogSIMA)\",\"volume\":\"199 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2016-03-21\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"45\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2016 IEEE International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision Support (CogSIMA)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/COGSIMA.2016.7497780\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 IEEE International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision Support (CogSIMA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/COGSIMA.2016.7497780","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 45

摘要

网络空间是日常生活中越来越重要的一部分。我们早就认识到,保卫这一空间是复杂的,需要信息集成,需要人与机器的决策在一个充满变化优先级的动态环境中结合起来。这些属性表明,与具有类似特征的其他领域一样,人类网络防御者的态势感知(SA)对网络防御决策结果的质量至关重要。现有的大多数网络态势感知研究都集中在信息系统和计算机上,它们将不同的数据拼凑在一起。例如,来自多个来源的融合数据对于网络空间可视化工作是必要的。从这个角度判断成功的网络安全与以人为中心的判断是不同的。相比之下,我们很少评估人类在网络空间的认知意识。在某种程度上,这反映了一种需求,基于先前的理论,首先定义人类必须感知的信息的关键元素,努力阐明人类如何结合这些元素来理解网络的状态,以及这种意识如何共同帮助分析人员预测网络的未来状态。换句话说,尽管数据融合可以通过减少拼凑不同信息源所产生的认知负荷来提供价值,但人类对网络的感知(网络认知态势感知- CCSA)可能是国防性能的最终中介。为了这样的理解,我们讨论了认知任务分析(CTA)的结果,该分析旨在确定网络分析师在网络防御中寻求的目标和抽象的意识元素。我们提出了一系列计划实验的基础,这些实验建立了CCSA测量,并为网络防御者的努力奠定了基础。一旦进行评估,我们就可以开始考虑融合系统、防御能力自动化和网络可视化所提供的帮助,这在方法上是严格的,而这些都是我们所缺乏的。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A task analysis toward characterizing cyber-cognitive situation awareness (CCSA) in cyber defense analysts
Cyberspace is an increasingly crucial part of everyday living. We have long recognized that defending this space is complex, requiring information integration, and decisions of man and machine to coalesce in a dynamic environment full of shifting priorities. These properties suggest that, as in other domains with similar characteristics, situation awareness (SA) of a human cyber defender is paramount to the quality of decision outcomes in cyber defense. The majority of existing research in cyber situation awareness, centers on information systems and computers, which piece together disparate data. Fused data from multiple sources, for example, is necessary for cyberspace visualization efforts. The judgment for successful cyber SA from this perspective is different from one that is human-centered. In comparison, we rarely assess human cognitive awareness in cyberspace. In part, this reflects a need, based on prior theory, to first define critical elements of information that the human must perceive, work to elucidate how humans combine these elements to comprehend the state of the network, and how together, this awareness helps analysts predict the future state of the network. In other words, although data fusion can provide value by reducing the cognitive load created to piece together disparate sources of information, human awareness of the network (cyber-cognitive situation awareness - CCSA) is perhaps the ultimate intermediary for defense performance. Toward such an understanding, we discuss the results of a cognitive task analysis (CTA) which sought to determine the goals and abstracted elements of awareness that cyber analysts seek in network defense. We present the foundation for a series of planned experiments that establishes CCSA measurement, and baselines the efforts of cyber defenders. Once assessed, we can then begin to consider the help offered by fusion systems, automation of defensive capabilities, and cyber visualizations in a methodologically rigorous manner that has been lacking.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信