恶意软件:恶意软件安全意识教育和事件响应培训桌面演练

Giddeon Angafor , Iryna Yevseyeva , Leandros Maglaras
{"title":"恶意软件:恶意软件安全意识教育和事件响应培训桌面演练","authors":"Giddeon Angafor ,&nbsp;Iryna Yevseyeva ,&nbsp;Leandros Maglaras","doi":"10.1016/j.iotcps.2024.02.003","DOIUrl":null,"url":null,"abstract":"<div><p>Advancements in technology, including the Internet of Things (IoT) revolution, have enabled individuals and businesses to use systems and devices that connect, exchange data, and provide real-time information from far and near. Despite that, this interconnectivity and data sharing between systems and devices over the internet poses security and privacy risks as threat actors can intercept, steal, and use owners’ data for nefarious purposes. This paper discusses ’MalAware’, a ‘Malware Awareness Education’ and incident response (IR) scenario-based tabletop exercise and card game for malware threat mitigation training. It introduces the importance of incident management, highlights the dangers posed by malware for connected systems, and outlines the role of tabletop games and exercises in helping businesses mature their malware incident response capabilities. The study discusses the design of MalAware and summarises the results of 2 pilots undertaken to assess the concept, maintaining that the results highlighted the value of ‘MalAware’ as an essential tool to help students and staff master how to mitigate security threats caused by malware. It argues that MalAware can assist businesses in their IR preparedness endeavors, enabling incident management teams to review plans and processes to ensure they are fit for purpose. It enables staff to leverage scenario-based and simulated security breach examples, including role-play, to establish appropriate malware defences. MalAware’s practical hands-on exercises can assist trainees in gaining essential malware and other threat mitigation skills, helping to protect the security and privacy of IoTs.</p></div>","PeriodicalId":100724,"journal":{"name":"Internet of Things and Cyber-Physical Systems","volume":"4 ","pages":"Pages 280-292"},"PeriodicalIF":0.0000,"publicationDate":"2024-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.sciencedirect.com/science/article/pii/S2667345224000063/pdfft?md5=61feca14037fa00f21581df14b5c4571&pid=1-s2.0-S2667345224000063-main.pdf","citationCount":"0","resultStr":"{\"title\":\"MalAware: A tabletop exercise for malware security awareness education and incident response training\",\"authors\":\"Giddeon Angafor ,&nbsp;Iryna Yevseyeva ,&nbsp;Leandros Maglaras\",\"doi\":\"10.1016/j.iotcps.2024.02.003\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><p>Advancements in technology, including the Internet of Things (IoT) revolution, have enabled individuals and businesses to use systems and devices that connect, exchange data, and provide real-time information from far and near. Despite that, this interconnectivity and data sharing between systems and devices over the internet poses security and privacy risks as threat actors can intercept, steal, and use owners’ data for nefarious purposes. This paper discusses ’MalAware’, a ‘Malware Awareness Education’ and incident response (IR) scenario-based tabletop exercise and card game for malware threat mitigation training. It introduces the importance of incident management, highlights the dangers posed by malware for connected systems, and outlines the role of tabletop games and exercises in helping businesses mature their malware incident response capabilities. The study discusses the design of MalAware and summarises the results of 2 pilots undertaken to assess the concept, maintaining that the results highlighted the value of ‘MalAware’ as an essential tool to help students and staff master how to mitigate security threats caused by malware. It argues that MalAware can assist businesses in their IR preparedness endeavors, enabling incident management teams to review plans and processes to ensure they are fit for purpose. It enables staff to leverage scenario-based and simulated security breach examples, including role-play, to establish appropriate malware defences. MalAware’s practical hands-on exercises can assist trainees in gaining essential malware and other threat mitigation skills, helping to protect the security and privacy of IoTs.</p></div>\",\"PeriodicalId\":100724,\"journal\":{\"name\":\"Internet of Things and Cyber-Physical Systems\",\"volume\":\"4 \",\"pages\":\"Pages 280-292\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2024-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://www.sciencedirect.com/science/article/pii/S2667345224000063/pdfft?md5=61feca14037fa00f21581df14b5c4571&pid=1-s2.0-S2667345224000063-main.pdf\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Internet of Things and Cyber-Physical Systems\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2667345224000063\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Internet of Things and Cyber-Physical Systems","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2667345224000063","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

技术的进步,包括物联网(IoT)革命,使个人和企业能够使用连接、交换数据和提供实时信息的系统和设备。尽管如此,系统和设备之间通过互联网实现的互联和数据共享也带来了安全和隐私风险,因为威胁行为者可以拦截、窃取和使用所有者的数据来达到邪恶目的。本文讨论的 "恶意软件 "是一种基于 "恶意软件意识教育 "和事件响应(IR)情景的桌面演练和卡片游戏,用于恶意软件威胁缓解培训。它介绍了事件管理的重要性,强调了恶意软件给联网系统带来的危险,并概述了桌面游戏和演习在帮助企业提高恶意软件事件响应能力方面的作用。该研究讨论了恶意软件的设计,总结了为评估这一概念而进行的两次试点的结果,认为这些结果突出了 "恶意软件 "作为帮助学生和教职员工掌握如何减轻恶意软件造成的安全威胁的重要工具的价值。报告认为,"恶意软件 "可以帮助企业做好爱尔兰共和军的准备工作,使事件管理团队能够审查计划和流程,确保其符合目的。它使员工能够利用基于场景和模拟的安全漏洞实例(包括角色扮演)建立适当的恶意软件防御。MalAware 的实际操作练习可以帮助学员获得基本的恶意软件和其他威胁缓解技能,从而帮助保护物联网的安全和隐私。
本文章由计算机程序翻译,如有差异,请以英文原文为准。

MalAware: A tabletop exercise for malware security awareness education and incident response training

MalAware: A tabletop exercise for malware security awareness education and incident response training

Advancements in technology, including the Internet of Things (IoT) revolution, have enabled individuals and businesses to use systems and devices that connect, exchange data, and provide real-time information from far and near. Despite that, this interconnectivity and data sharing between systems and devices over the internet poses security and privacy risks as threat actors can intercept, steal, and use owners’ data for nefarious purposes. This paper discusses ’MalAware’, a ‘Malware Awareness Education’ and incident response (IR) scenario-based tabletop exercise and card game for malware threat mitigation training. It introduces the importance of incident management, highlights the dangers posed by malware for connected systems, and outlines the role of tabletop games and exercises in helping businesses mature their malware incident response capabilities. The study discusses the design of MalAware and summarises the results of 2 pilots undertaken to assess the concept, maintaining that the results highlighted the value of ‘MalAware’ as an essential tool to help students and staff master how to mitigate security threats caused by malware. It argues that MalAware can assist businesses in their IR preparedness endeavors, enabling incident management teams to review plans and processes to ensure they are fit for purpose. It enables staff to leverage scenario-based and simulated security breach examples, including role-play, to establish appropriate malware defences. MalAware’s practical hands-on exercises can assist trainees in gaining essential malware and other threat mitigation skills, helping to protect the security and privacy of IoTs.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
13.80
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信