The dynamics of cyber threats are increasingly complex, making it more challenging than ever for organizations to obtain in-depth insights into their cyber security status. Therefore, organizations rely on Cyber Situational Awareness (CSA) to support them in better understanding the threats and associated impacts of cyber events. Due to the heterogeneity and complexity of cyber security data, often with multidimensional attributes, sophisticated visualization techniques are often needed to achieve CSA. However, there have been no attempts to systematically review and analyze scientific literature on CSA visualizations until now. In this paper, we have systematically selected and reviewed 54 publications that discuss visualizations to support CSA. We extracted data from these papers to identify key stakeholders, information types, data sources, and visualization techniques. Furthermore, we analyze the level of CSA supported by the visualizations, maturity of the visualizations, challenges, and practices related to CSA visualizations to prepare a full analysis of the current state of CSA in the organizational context. Our results reveal certain gaps in CSA visualizations. For instance, the most focus is on operational-level staff and there is a clear lack of visualizations targeting other types of stakeholders such as managers, higher-level decision makers, and non-expert users. Most papers focus on threat information visualization and there is a lack of papers that visualize impact information, response plans, and information shared within teams. Interestingly, only a few studies proposed visualizations to facilitate up to projection level (i.e. the highest level of CSA) whereas most studies facilitated perception level (i.e. the lowest level of CSA). Based on the results that highlight the important concerns in CSA visualizations, we recommend a list of future research directions.
翻译:网络威胁的动态日益复杂,使得各组织更难获得对其网络安全状况的深入洞察力,因此,各组织依靠网络情况认知系统(CSA)支持它们更好地了解网络事件的威胁及其相关影响。由于网络安全数据的异质性和复杂性,往往需要复杂的视觉化技术来实现CSA。然而,到目前为止,还没有尝试系统地审查和分析关于CSA视觉化的科学文献。在本文中,我们系统挑选和审查了54份讨论可视化以支持CSA的可视化的出版物。我们从这些文件中提取了数据,以查明关键利益攸关方、信息类型、数据来源和可视化技术。此外,我们分析了CSA的水平,由于网络安全数据的可视化、视觉化的成熟、挑战和做法而支持了网络安全数据的多样化和复杂性,以便全面分析CSA的组织背景化现状。我们的结果显示CSA的直观化存在某些差距。例如,最侧重于业务层面的工作人员,而且没有清晰的直观化数据,而最明显缺乏针对其他类型用户的图像化影响。CSA层次的研究、CSA层次的拟议反应水平,我们建议了CSAL级文件的深度反应水平。