[论文解读] Elicitation of SME Requirements for Cybersecurity Solutions by Studying Adherence to Recommendations
本文提出了一种新颖的方法,通过分析专家建议在现实世界中的遵循情况,来获取中小型企业(SMEs)的网络安全需求。通过将采纳的建议视为需求对齐的指标,将被放弃的建议视为未满足需求的信号,该方法借助CYSEC工具实现了可扩展的、上下文感知的需求获取,该工具可捕捉并分析专家指导,以指导解决方案设计。
Small and medium-sized enterprises (SME) have become the weak spot of our economy for cyber attacks. These companies are large in number and often do not have the controls in place to prevent successful attacks, respectively are not prepared to systematically manage their cybersecurity capabilities. One of the reasons for why many SME do not adopt cybersecurity is that developers of cybersecurity solutions understand little the SME context and the requirements for successful use of these solutions. We elicit requirements by studying how cybersecurity experts provide advice to SME. The experts recommendations offer insights into what important capabilities of the solution are and how these capabilities ought to be used for mitigating cybersecurity threats. The adoption of a recommendation hints at a correct match of the solution, hence successful consideration of requirements. Abandoned recommendations point to a misalignment that can be used as a source to inquire missed requirements. Re-occurrence of adoption or abandonment decisions corroborate the presence of requirements. This poster describes the challenges of SME regarding cybersecurity and introduces our proposed approach to elicit requirements for cybersecurity solutions. The poster describes CYSEC, our tool used to capture cybersecurity advice and help to scale cybersecurity requirements elicitation to a large number of participating SME. We conclude by outlining the planned research to develop and validate CYSEC.
研究动机与目标
- 解决由于网络安全解决方案与中小型企业实际运营背景不匹配而导致的采纳率低下的关键问题。
- 通过分析中小型企业采纳或拒绝专家建议的情况,识别现有网络安全解决方案中未满足的需求。
- 开发一种可扩展的方法,从现实世界专家建议中获取可操作的、与上下文相关的具体需求。
- 开发并验证CYSEC工具,以系统化地捕捉和分析网络安全建议,用于需求挖掘。
提出的方法
- 通过结构化访谈或咨询,从专家处收集针对中小企业的现实世界网络安全建议。
- 根据中小型企业对建议的采纳或放弃情况,对建议进行分类,以推断需求对齐程度。
- 将采纳或放弃决策的重复出现作为稳定、反复出现的需求存在的证据。
- 应用CYSEC专用工具,存储、跟踪并分析多个中小企业互动中的建议模式。
- 将建议的行动映射到潜在的解决方案能力与用户需求,以推导出功能性和非功能性需求。
- 利用定性分析与模式识别,从被拒绝的建议中推断出缺失或不匹配的需求。
实验结果
研究问题
- RQ1如何利用现实世界中小企业网络安全咨询中的专家建议,推断出未满足的需求?
- RQ2在建议采纳或放弃行为中,哪些模式表明存在关键且反复出现的需求?
- RQ3CYSEC工具在多大程度上能有效扩展针对中小企业网络安全需求的获取?
- RQ4从中小企业的视角来看,不匹配的建议如何揭示当前网络安全解决方案中的缺口?
- RQ5网络安全解决方案必须具备哪些关键能力,才能确保中小企业的采纳?
主要发现
- 专家建议的采纳与解决方案能力的对齐程度密切相关,表明其是有效的需求信号。
- 在多个中小企业中反复放弃特定建议,揭示了现有解决方案中持续存在的未满足需求。
- 在不同中小企业中重复出现的相似采纳或拒绝模式,证实了所识别需求的稳定性和重要性。
- CYSEC工具成功捕捉并结构化了专家建议,实现了对建议模式的系统性分析。
- 专家建议可作为识别中小企业网络安全解决方案中功能性和情境性需求的可靠代理。
- 该方法能够通过遵循模式识别出非功能性需求,如易用性、集成简便性以及运营适配性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。