Title | ||
---|---|---|
A Feedback-Based Evaluation Approach for the Continuous Adjustment of Incident Prioritization |
Abstract | ||
---|---|---|
Incident Prioritization is a technique that evaluates security incidents to derive a priority in order to enable an analyst to focus on the most important events first. It is traditionally based on a set of static calculations, which are rarely adjusted. Especially since there is no explicit process to identify errors and improvements are made and evaluated manually on a best guess basis. This leads to issues when changes occur, as due to shifting concepts, new entities and attacks or changing guidelines. In this paper, we discuss the requirements and an approach to assist in a continuous tuning of the incident prioritization model. We develop a process that involves feedback from an analyst in order to evaluate potential improvements. This process includes mechanisms to quickly identify incorrect ratings and supports the selection of a new model and its establishment. |
Year | DOI | Venue |
---|---|---|
2018 | 10.1109/ICDIS.2018.00036 | 2018 1st International Conference on Data Intelligence and Security (ICDIS) |
Keywords | Field | DocType |
Network Security,Incident Prioritization,Feedback based Adaptation,Multi objective Optimization | Data mining,Anomaly detection,Task analysis,Computer science,Prioritization | Conference |
ISBN | Citations | PageRank |
978-1-5386-5763-8 | 2 | 0.50 |
References | Authors | |
3 | 4 |
Name | Order | Citations | PageRank |
---|---|---|---|
Leonard Renners | 1 | 4 | 2.74 |
Felix Heine | 2 | 18 | 5.24 |
Carsten Kleiner | 3 | 73 | 21.21 |
Gabi Dreo Rodosek | 4 | 134 | 44.97 |