Title
A Study on the State of Practice in Security Situational Awareness
Abstract
We present the results of an interview study on the state of practice for Situational Awareness (SA) in the cybersecurity industry. Representatives from four global companies providing cybersecurity monitoring and analysis services and products were interviewed to get a view into the current state of practice in SA. The interviews were performed as a form of thematic interview, resulting in the classification of the results in three main areas of SA, i.e., how security is modelled, what information is collected, and how the data is analyzed. We describe the topics covered by the interviews, the common issues and methods, their differences, and provide a summary view on the current state of security monitoring and analysis in the cybersecurity industry. We also describe potential future work in terms of identified challenges in the area. The results help understand various aspects of cybersecurity situational awareness, to identify gaps between research and practice, and to build holistic SA solutions.
Year
DOI
Venue
2016
10.1109/QRS-C.2016.14
2016 IEEE International Conference on Software Quality, Reliability and Security Companion (QRS-C)
Keywords
Field
DocType
security,situational awareness,monitoring,analysis
Interview study,Data visualization,Situation awareness,Knowledge management,Security monitoring,Engineering
Conference
ISBN
Citations 
PageRank 
978-1-5090-3714-8
2
0.43
References 
Authors
15
2
Name
Order
Citations
PageRank
Teemu Kanstrén13610.59
Antti Evesti210211.02