The dynamics of cyber threats are increasingly complex, making it more challenging than ever for organizations to obtain in-depth insights into their cyber security status. Therefore, organizations rely on Cyber Situational Awareness (CSA) to support them in better understanding the threats and associated impacts of cyber events. Due to the heterogeneity and complexity of cyber security data, often with multidimensional attributes, sophisticated visualization techniques are needed to achieve CSA. However, there have been no previous attempts to systematically review and analyze the scientific literature on CSA visualizations. In this paper, we systematically select and review 54 publications that discuss visualizations to support CSA. We extract data from these papers to identify key stakeholders, information types, data sources, and visualization techniques. Furthermore, we analyze the level of CSA supported by the visualizations, alongside examining the maturity of the visualizations, challenges, and practices related to CSA visualizations to prepare a full analysis of the current state of CSA in an organizational context. Our results reveal certain gaps in CSA visualizations. For instance, the largest focus is on operational-level staff, and there is a clear lack of visualizations targeting other types of stakeholders such as managers, higher-level decision makers, and non-expert users. Most papers focus on threat information visualization, and there is a dearth of papers that visualize impact information, response plans, and information shared within teams. Based on the results that highlight the important concerns in CSA visualizations, we recommend a list of future research directions.
翻译:网络威胁的动态日益复杂,使得各组织更难以深入了解其网络安全状况。因此,各组织依靠网络情况认知系统支持它们更好地了解网络事件的威胁和相关影响。由于网络安全数据的多样性和复杂性,往往具有多层面特征,因此需要复杂的视觉化技术来实现网络安全数据。然而,过去没有尝试系统地审查和分析关于CSA视觉化的科学文献。在本文中,我们系统地挑选和审查54份讨论可视化以支持CSA的出版物。我们从这些文件中提取数据,以确定关键利益攸关方、信息类型、数据来源和可视化技术。此外,我们分析CSA的可视化支持水平,同时审查与CSA视觉化有关的成熟性、挑战和做法,以便从组织角度全面分析CSA的当前状况。我们的结果揭示了CSA视觉化的某些差距。例如,最大的重点是业务层面的工作人员,从这些文件中提取数据,我们从这些文件中提取的可视化程度明显缺乏视觉化的数据。