Skip to main content
QUICK REVIEW

[论文解读] Human Behaviour as an aspect of Cyber Security Assurance

Mark Evans, Λέανδρος Μαγλαράς|arXiv (Cornell University)|Jan 15, 2016
Information and Cyber Security参考文献 11被引用 4
一句话总结

本文提出了一种以人为中心的网络安保保障框架,通过将人为可靠性评估与统计质量控制整合到安全流程中,以提升安全保障水平。文章指出,人为行为对安全态势具有显著影响,并呼吁采用可重复、可量化的指标来改进保障机制,特别是通过结构化评估方法来减轻人为引入的漏洞。

ABSTRACT

There continue to be numerous breaches publicised pertaining to cyber security despite security practices being applied within industry for many years. This article is intended to be the first in a number of articles as research into cyber security assurance processes. This article is compiled based on current research related to cyber security assurance and the impact of the human element on it. The objective of this work is to identify elements of cyber security that would benefit from further research and development based on the literature review findings. The results outlined in this article present a need for the cyber security field to look in to established industry areas to benefit from effective practices such as human reliability assessment, along with improved methods of validation such as statistical quality control in order to obtain true assurance. The article proposes the development of a framework that will be based upon defined and repeatable quantification, specifically relating to the range of human aspect tasks that provide, or are intended not to negatively affect cyber security posture.

研究动机与目标

  • 识别当前网络安全保障实践中与人为行为相关的漏洞。
  • 解决尽管已有既定安全措施,但安全事件仍持续发生的问题。
  • 倡导将人为可靠性评估与统计质量控制整合到网络安全保障框架中。
  • 开发一种可重复、可量化的评估方法,用于衡量网络安全中的人为因素。

提出的方法

  • 对网络安全保障与人为因素相关文献进行综述。
  • 借鉴核能与航空等行业在人为可靠性评估方面的成熟实践。
  • 提出一种基于可定义、可重复量化影响安全的人为任务的框架。
  • 整合统计质量控制技术以验证安全流程。
  • 聚焦于人为行为可能对网络安全态势产生积极或消极影响的任务。
  • 基于实证研究结果,指导可度量保障模型的设计。

实验结果

研究问题

  • RQ1人为行为如何影响网络安全保障流程的有效性?
  • RQ2现有行业实践中有何可借鉴的范例,以改善与人为因素相关的安全保障?
  • RQ3如何在网络安全框架中量化并验证人为可靠性?
  • RQ4采用何种方法可确保对安全中人为因素的可重复、可测量评估?
  • RQ5统计质量控制在提升网络安全保障中发挥何种作用?

主要发现

  • 尽管已有既定安全措施,人为行为仍是网络安全事件中一个关键且常被忽视的因素。
  • 当前的保障方法缺乏对人为因素的系统性评估,导致结果不一致。
  • 高风险行业中的人为可靠性评估技术可被调整应用于提升网络安全保障。
  • 统计质量控制为验证安全流程并确保一致性提供了切实可行的方法。
  • 迫切需要可重复、可量化的指标来评估人为因素对安全态势的贡献。
  • 将以人为中心的评估整合到保障框架中,可显著提升整体安全有效性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。