ARIMA Supplemented Security Metrics for Quality Assurance and Situational Awareness

被引:3
作者
Kohlrausch, Jan [1 ]
Brin, Eugene A. [1 ]
机构
[1] DFN CERT, Nagelsweg 41, Hamburg, Germany
来源
DIGITAL THREATS: RESEARCH AND PRACTICE | 2020年 / 1卷 / 01期
基金
欧盟地平线“2020”;
关键词
ARIMA supplemented metrics; CSIRT services; threat intelligence; situational awareness; quality control; ARIMA; prediction based anomaly detection; time series analysis; SCIENCE; DESIGN;
D O I
10.1145/3376926
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Quality assurance and situational awareness are important areas of interest for CSIRTs and security teams. Significant efforts have been made on defining metrics measuring critical parameters for these fields of application. However, methodical approaches are missing or lacking precision to enable a reliable usage of such metrics for quality assurance and situational awareness. In this contribution, we introduce a method that generalizes the application of ARIMA time series analysis on a well-defined set of metrics (ARIMA supplemented metrics) to facilitate and support quality assurance and situational awareness services. This method is based on research on ARIMA models and metrics and builds on CSIRT best practices. We show how data analysts and security practitioners can incorporate this method into existing best practices for CSIRT services pertaining to quality assurance and situational awareness. The applicability of this method is demonstrated by integrating ARIMA supplemented metrics into exemplary processes for quality assurance and situational awareness to support data analysts and security practitioners in CSIRTs and security teams.
引用
收藏
页数:21
相关论文
共 41 条
  • [1] ACDC Project Consortium, 2015, Advanced Cyber Defence Centre (ACDC)
  • [2] American Society for Quality (ASQ), 2019, Quality Assurance & Quality Control
  • [3] [Anonymous], 2010, The CIS Security Metrics
  • [4] Black P., 2009, Cyber Security Metrics and Measures, DOI DOI 10.1002/9780470087923.HHS440
  • [5] Box G. E., 1976, Time Series Analysis: Forecasting and Control
  • [6] INTERVENTION ANALYSIS WITH APPLICATIONS TO ECONOMIC AND ENVIRONMENTAL PROBLEMS
    BOX, GEP
    TIAO, GC
    [J]. JOURNAL OF THE AMERICAN STATISTICAL ASSOCIATION, 1975, 70 (349) : 70 - 79
  • [7] Calder Alan, 2009, Information Security Based on ISO 27001/ISO 27002: A Management Guide-Best Practice
  • [8] Cheng Y., 2014, METRICS SECURITY, P263, DOI DOI 10.1007/978-3-319-11391-3_13
  • [9] Cosmin Ciobanu (ENISA), 2015, A report by the ENISA Ad Hoc Working Group on Privacy and Technology
  • [10] Cryer JD, 2008, SPRINGER TEXTS STAT, P1