DocumentCode :
263557
Title :
Beyond technical data - a more comprehensive situational awareness fed by available intelligence information
Author :
Kornmaier, Andreas ; Jaouen, Fabrice
Author_Institution :
Fac. of Comput. Sci., Univ. der Bundeswehr Munchen, Neubiberg, Germany
fYear :
2014
fDate :
3-6 June 2014
Firstpage :
139
Lastpage :
154
Abstract :
Information on cyber incidents and threats are currently collected and processed with a strong technical focus. Threat and vulnerability information alone are not a solid base for effective, affordable or actionable security advice for decision makers. They need more than a small technical cut of a bigger situational picture to combat and not only to mitigate the cyber threat. We first give a short overview over the related work that can be found in the literature. We found that the approaches mostly analysed “what” has been done, instead of looking more generically beyond the technical aspects for the tactics, techniques and procedures to identify the “how” it was done, by whom and why. We examine then, what information categories and data already exist to answer the question for an adversary´s capabilities and objectives. As traditional intelligence tries to serve a better understanding of adversaries´ capabilities, actions, and intent, the same is feasible in the cyber space with cyber intelligence. Thus, we identify information sources in the military and civil environment, before we propose to link that traditional information with the technical data for a better situational picture. We give examples of information that can be collected from traditional intelligence for correlation with technical data. Thus, the same intelligence operational picture for the cyber sphere could be developed like the one that is traditionally fed from conventional intelligence disciplines. Finally we propose a way of including intelligence processing in cyber analysis. We finally outline requirements that are key for a successful exchange of information and intelligence between military/civil information providers.
Keywords :
decision making; information resources; security of data; adversary capabilities; civil environment; civil information providers; cyber analysis; cyber incidents; cyber intelligence; cyber space; cyber threats; decision makers; information categories; information sources; intelligence information; intelligence processing; military environment; military information providers; situational awareness; technical data; threat information; vulnerability information; Bibliographies; Charge coupled devices; Context; Decision making; Malware; Solids; cyber; cyber intelligence; information collection fusion; intelligence;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Cyber Conflict (CyCon 2014), 2014 6th International Conference On
Conference_Location :
Tallinn
ISSN :
2325-5366
Print_ISBN :
978-9949-9544-0-7
Type :
conf
DOI :
10.1109/CYCON.2014.6916400
Filename :
6916400
Link To Document :
بازگشت