Information sharing is vital in resisting cyberattacks, and the volume and severity of these attacks is increasing very rapidly. Therefore responders must triage incoming warnings in deciding how to act. This study asked a very specific question: "how can the addition of confidence information to alerts and warnings improve overall resistance to cyberattacks." We sought, in particular, to identify current practices, and if possible, to identify some "best practices." The research involved literature review and interviews with subject matter experts at every level from system administrators to persons who develop broad principles of policy. An innovative Modified Online Delphi Panel technique was used to elicit judgments and recommendations from experts who were able to speak with each other and vote anonymously to rank proposed practices.
翻译:信息分享对于抵制网络攻击至关重要,而这些攻击的数量和严重程度正在迅速增加。因此,响应者必须在决定如何行动时对收到的警告进行分类。本研究提出了一个非常具体的问题:“如何在警报和警报中增加信任信息,以提高对网络攻击的总体抵抗力?”我们特别寻求确定当前的做法,并在可能的情况下,确定一些“最佳做法”。研究涉及从系统管理员到制定广泛政策原则的各级专题专家的文献审查和访谈。 创新的在线德尔菲小组技术被用来征求能够相互交谈并匿名投票确定拟议做法的专家们的判断和建议。