4.7 Article

Effects of cyber security knowledge on attack detection

期刊

COMPUTERS IN HUMAN BEHAVIOR
卷 48, 期 -, 页码 51-61

出版社

PERGAMON-ELSEVIER SCIENCE LTD
DOI: 10.1016/j.chb.2015.01.039

关键词

Cyber security; Knowledge; Dynamic decision-making; Intrusion-detection system; Expertise

资金

  1. Multidisciplinary University Research Initiative Award (MURI) from Army Research Office [W911NF-09-1-0525]
  2. Army Research Laboratory [W911NF-13-2-0045]

向作者/读者索取更多资源

Ensuring cyber security is a complex task that relies on domain knowledge and requires cognitive abilities to determine possible threats from large amounts of network data. This study investigates how knowledge in network operations and information security influence the detection of intrusions in a simple network. We developed a simplified Intrusion Detection System (IDS), which allows us to examine how individuals with or without knowledge in cyber security detect malicious events and declare an attack based on a sequence of network events. Our results indicate that more knowledge in cyber security facilitated the correct detection of malicious events and decreased the false classification of benign events as malicious. However, knowledge had less contribution when judging whether a sequence of events representing a cyber-attack. While knowledge of cyber security helps in the detection of malicious events, situated knowledge regarding a specific network at hand is needed to make accurate detection decisions. Responses from participants that have knowledge in cyber security indicated that they were able to distinguish between different types of cyber-attacks, whereas novice participants were not sensitive to the attack types. We explain how these findings relate to cognitive processes and we discuss their implications for improving cyber security. (C) 2015 Elsevier Ltd. All rights reserved.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.7
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据