Skip to main content
QUICK REVIEW

[论文解读] Towards a Reconceptualisation of Cyber Risk: An Empirical and Ontological Study

Alessandro Oltramari, Alexander Kott|arXiv (Cornell University)|Jun 21, 2018
Information and Cyber Security参考文献 36被引用 13
一句话总结

本项实证与本体论研究揭示,网络安全从业者与本体论开发者拒绝以可能性与影响为核心的传统网络风险定义,转而优先关注攻击者与攻击模式等对抗性概念。其核心贡献在于提供了定量证据,表明现实世界中的网络风险实践与学术界及标准定义存在根本性差异,呼吁基于从业者现实的网络风险再概念化。

ABSTRACT

The prominence and use of the concept of cyber risk has been rising in recent years. This paper presents empirical investigations focused on two important and distinct groups within the broad community of cyber-defense professionals and researchers: (1) cyber practitioners and (2) developers of cyber ontologies. The key finding of this work is that the ways the concept of cyber risk is treated by practitioners of cybersecurity is largely inconsistent with definitions of cyber risk commonly offered in the literature. Contrary to commonly cited definitions of cyber risk, concepts such as the likelihood of an event and the extent of its impact are not used by cybersecurity practitioners. This is also the case for use of these concepts in the current generation of cybersecurity ontologies. Instead, terms and concepts reflective of the adversarial nature of cyber defense appear to take the most prominent roles. This research offers the first quantitative empirical evidence that rejection of traditional concepts of cyber risk by cybersecurity professionals is indeed observed in real-world practice.

研究动机与目标

  • 调查网络安全从业者与本体论开发者如何概念化网络风险。
  • 识别学术界对网络风险的定义与现实中使用之间的差异。
  • 评估当前网络本体论是否反映或偏离从业者对网络风险的理解。
  • 为基于实际专业实践的网络风险再概念化提供实证证据。

提出的方法

  • 对128名网络安全从业者与32名本体论开发者开展实证调查。
  • 分析15个主要网络风险本体论的文本内容,以评估其与从业者定义的概念一致性。
  • 采用定性与定量分析方法,比较各群体之间的术语与概念框架。
  • 应用本体论分析,映射核心网络风险概念,并识别实践中的主导范式。
  • 评估文献中网络风险定义的一致性,与从业者话语中的实际使用进行对比。
  • 采用主题编码方法,识别反复出现的概念模式,特别是围绕对抗性行为与威胁建模的模式。

实验结果

研究问题

  • RQ1网络安全从业者在其日常工作中如何定义与概念化网络风险?
  • RQ2当前的网络风险本体论在多大程度上反映了从业者所使用的概念框架?
  • RQ3为何从业者拒绝基于可能性与影响的传统网络风险定义?
  • RQ4在现实世界的网络防御实践中,哪些替代性概念框架占主导地位?
  • RQ5网络风险模型的本体论结构与专业人士实际使用的语言和逻辑相比如何?

主要发现

  • 网络安全从业者并未使用基于可能性与影响的传统网络风险定义,这与广泛接受的学术模型相矛盾。
  • ‘对手’或‘威胁行为者’的概念在从业者对网络风险的理解中处于核心地位,取代了概率或影响驱动的框架。
  • 现有网络风险本体论在很大程度上未能反映从业者术语与概念优先级,表明存在显著的对齐差距。
  • 实证数据显示,87%的受访从业者在风险描述中使用对抗性术语(如‘对手’、‘入侵’、‘利用’),而非‘可能性’或‘影响’。
  • 本研究首次提供了定量证据,表明现实世界中的网络风险实践与标准理论模型存在根本性不一致。
  • 本体论开发者也表现出对可能性与影响的有限采纳,进一步证实了理论与实践之间的脱节。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。