Title
Adaptive and Intelligible Prioritization for Network Security Incidents
Abstract
Incident prioritization is nowadays a part of many approaches and tools for network security and risk management. However, the dynamic nature of the problem domain is often unaccounted for. That is, the prioritization is typically based on a set of static calculations, which are rarely adjusted. As a result, incidents are incorrectly prioritized, leading to an increased and misplaced effort in the incident response. A higher degree of automation could help to address this problem. In this paper, we explicitly consider flaws in the prioritization an unalterable circumstance. We propose an adaptive incident prioritization, which allows to automate certain tasks for the prioritization model management in order to continuously assess and improve a prioritization model. At the same time, we acknowledge the human analyst as the focal point and propose to keep the human in the loop, among others by treating understandability as a crucial requirement.
Year
DOI
Venue
2019
10.1109/CyberSecPODS.2019.8885208
2019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security)
Keywords
Field
DocType
incident prioritization,network security,cyber security,adaptive learning
Anomaly detection,Telecommunications network,Task analysis,Problem domain,Computer science,Network security,Automation,Risk analysis (engineering),Risk management,Human-in-the-loop
Conference
ISBN
Citations 
PageRank 
978-1-7281-0230-6
0
0.34
References 
Authors
6
4
Name
Order
Citations
PageRank
Leonard Renners142.74
Felix Heine201.69
Carsten Kleiner37321.21
Gabi Dreo Rodosek413444.97