[论文解读] Architectural Tactics for Big Data Cybersecurity Analytic Systems: A Review
本篇系统文献综述识别出12项关键质量属性和17项软件架构策略(如数据分区、异常检测和容错)——这些对于大数据网络安全分析系统至关重要。研究揭示了在互操作性、隐私保护和适应性方面架构支持存在显著缺口,并呼吁通过实证验证和产学研合作来解决策略之间的权衡问题。
Context: Big Data Cybersecurity Analytics is aimed at protecting networks, computers, and data from unauthorized access by analysing security event data using big data tools and technologies. Whilst a plethora of Big Data Cybersecurity Analytic Systems have been reported in the literature, there is a lack of a systematic and comprehensive review of the literature from an architectural perspective. Objective: This paper reports a systematic review aimed at identifying the most frequently reported quality attributes and architectural tactics for Big Data Cybersecurity Analytic Systems. Method: We used Systematic Literature Review (SLR) method for reviewing 74 primary studies selected using well-defined criteria. Results: Our findings are twofold: (i) identification of 12 most frequently reported quality attributes and the justification for their significance for Big Data Cybersecurity Analytic Systems; and (ii) identification and codification of 17 architectural tactics for addressing the quality attributes that are commonly associated with Big Data Cybersecurity Analytic systems. The identified tactics include six performance tactics, four accuracy tactics, two scalability tactics, three reliability tactics, and one security and usability tactic each. Conclusion: Our findings have revealed that (a) despite the significance of interoperability, modifiability, adaptability, generality, stealthiness, and privacy assurance, these quality attributes lack explicit architectural support in the literature (b) empirical investigation is required to evaluate the impact of codified architectural tactics (c) a good deal of research effort should be invested to explore the trade-offs and dependencies among the identified tactics and (d) there is a general lack of effective collaboration between academia and industry for supporting the field of Big Data Cybersecurity Analytic Systems.
研究动机与目标
- 从架构视角出发,识别并分析大数据网络安全分析系统中最常报告的质量属性。
- 对文献中用于应对这些质量属性的架构策略进行分类与编码。
- 突出强调现有系统在隐私、互操作性和可修改性等关键属性方面架构支持的不足。
- 呼吁对架构策略进行实证验证,并进一步研究策略之间的权衡与依赖关系。
- 鼓励学术界与产业界加强合作,以推动大数据网络安全分析领域的发展。
提出的方法
- 采用预定义的纳入与排除标准,开展系统文献综述(SLR),从文献中筛选出74篇原始研究。
- 使用主题编码与分类方法,提取并分析所选研究中报告的质量属性与架构策略。
- 将识别出的架构策略归类为五类:性能、准确性、可扩展性、可靠性和安全性/可用性。
- 评估每项质量属性与策略的出现频率及其理由,以确定其在系统设计中的重要性。
- 采用结构化综合方法,识别架构决策中的重复模式、缺口与研究机遇。
- 将研究发现分类为对系统架构师与研究人员具有实际意义的见解,特别强调关键质量属性中尚未满足的需求。
实验结果
研究问题
- RQ1在大数据网络安全分析系统中,哪些质量属性被最频繁地报告?为何它们被视为关键?
- RQ2为应对这些质量属性,通常采用哪些架构策略?它们如何被分类?
- RQ3在现有系统中,架构决策对隐私、互操作性和适应性等关键质量属性的支持程度如何?
- RQ4在质量属性的架构支持方面存在哪些主要缺口?这些缺口对系统设计有何影响?
- RQ5在大数据网络安全分析系统的开发过程中,学术界与产业界之间存在哪些主要的研究与合作缺口?
主要发现
- 识别出12项最常报告的关键质量属性,包括性能、准确性、可扩展性、可靠性和安全性。
- 共编码了17项架构策略,包括6项性能策略、4项准确性策略、2项可扩展性策略、3项可靠性策略,以及各1项安全性与可用性策略。
- 尽管这些属性至关重要,但文献中缺乏对互操作性、可修改性、适应性、通用性、隐蔽性及隐私保障的明确架构支持。
- 目前缺乏实证研究来评估所识别架构策略在现实世界中的实际影响。
- 亟需开展更多研究,以探索架构策略之间的权衡与依赖关系,从而指导整体系统设计。
- 普遍观察到学术界与产业界之间缺乏合作,阻碍了大数据网络安全分析系统在实践中的进一步发展。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。