Skip to main content
QUICK REVIEW

[论文解读] Honeypots for employee information security awareness and education training: A conceptual EASY training model

Lek Christopher, Kim‐Kwang Raymond Choo|arXiv (Cornell University)|Jun 25, 2017
Cybercrime and Law Enforcement Studies参考文献 15被引用 6
一句话总结

本文提出EASY训练模型——参与利益相关者、可接受行为、简单教学、基准衡量——利用新加坡一所大学的真实蜜罐数据,以提升员工的信息安全意识与教育。通过应用例行活动理论,该模型将实时网络攻击数据转化为互动式培训内容,证明蜜罐能有效暴露员工的安全漏洞,并通过体验式学习改善安全文化。

ABSTRACT

The increasing pervasiveness of internet-connected systems means that such systems will continue to be exploited for criminal purposes by cybercriminals (including malicious insiders such as employees and vendors). The importance of protecting corporate system and intellectual property, and the escalating complexities of the online environment underscore the need for ongoing information security awareness and education training and the promotion of a culture of security among employees. Two honeypots were deployed at a private university based in Singapore. Findings from the analysis of the honeypot data are presented in this paper. This paper then examines how analysis of honeypot data can be used in employee information security awareness and education training. Adapting the Routine Activity Theory, a criminology theory widely used in the study of cybercrime, this paper proposes a conceptual Engaging Stakeholders, Acceptable Behavior, Simple Teaching method, Yardstick (EASY) training model, and explains how the model can be used to design employee information security awareness and education training. Future research directions are also outlined in this paper.

研究动机与目标

  • 通过提升员工的信息安全意识与教育,应对日益增长的内部网络攻击威胁。
  • 通过识别暴露系统于网络威胁的员工行为,降低组织风险。
  • 利用真实蜜罐数据,开发一种实用且基于理论的培训模型,用于信息安全教育。
  • 通过基于实际攻击模式的体验式学习,推动主动的安全文化建设。
  • 弥合理论安全培训与真实世界网络攻击暴露之间的差距。

提出的方法

  • EASY训练模型基于例行活动理论,该理论从有动机的攻击者、合适的攻击目标以及缺乏监管三个维度解释犯罪行为。
  • 在新加坡一所私立大学部署了两个蜜罐,用以模拟易受攻击的系统,并捕获真实的网络攻击尝试。
  • 分析蜜罐数据(包括IP地址、攻击类型和时间)以识别常见的攻击模式及与员工相关的安全风险。
  • 利用分析结果设计针对性的培训模块,聚焦于现实威胁与员工行为。
  • 该模型强调利益相关者参与、可接受行为的明确定义、简洁的教学内容以及可衡量的基准(即基准衡量)。
  • 培训方法将真实攻击数据整合到案例研究与模拟中,以提升内容的相关性与记忆效果。

实验结果

研究问题

  • RQ1如何有效利用蜜罐生成的数据来提升员工的信息安全意识与教育?
  • RQ2员工行为在多大程度上暴露了系统漏洞?这一问题通过蜜罐部署得以揭示。
  • RQ3如何将例行活动理论适配以设计一种实用的信息安全培训模型?
  • RQ4构建一个引人入胜、以行为为导向的安全培训项目,其关键构成要素是什么?
  • RQ5如何将真实网络攻击数据转化为员工可执行的培训内容?

主要发现

  • 蜜罐成功捕获了多次网络攻击尝试,包括端口扫描、暴力破解攻击和恶意软件探测,表明组织的数字攻击面正受到主动针对。
  • 分析显示,部分攻击源自内部网络,暗示可能存在内部威胁或被攻陷的员工设备。
  • EASY模型成功地将真实攻击数据转化为培训内容,显著提升了信息安全教育的相关性与参与度。
  • 该模型聚焦于可接受行为与明确的基准,帮助员工理解具体的安全期望及其后果。
  • 将真实蜜罐数据整合到培训中,相比通用的理论教学,显著提升了意识培训的现实感与影响力。
  • 本研究证明,蜜罐不仅作为检测工具有效,还可作为培育安全意识文化的重要教育资源。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。