Publications

Towards an operations-aware experimentation methodology

Abstract

Security Operations Centers (SOCs) serve a critical role in protecting enterprise networks and systems. Despite this critical role, only a limited number of researchers in the field have an awareness of the obstacles and challenges in applying cyber ranges and cybersecurity testbeds to the area of SOC training, exercises and evaluation. This paper introduces a systematic approach to incorporating SOCs into cybersecu-rity experiments, including both training and evaluation. We present a reference SOC model, an implementation of that model and downloadable software distributions suitable for deploying on cyber ranges, and guidance towards a methodol-ogy to promote rigorous experiments including those involving human cyber operators. Metrics focused on analyst event load are presented in the context of measuring the impact of new threats, technologies and procedures on SOC performance. Collectively …

Date
June 6, 2022
Authors
Michael Collins, Alefiya Hussain, Stephen Schwab
Conference
2022 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
Pages
384-393
Publisher
IEEE