140 likes | 153 Views
Models of Information Security Analysis. Outline. Definitions Analysis framework Cautionary factors Sample analysis. Definitions. Trend: to extend in a general direction: follow a general course or veer in a new direction
E N D
Outline • Definitions • Analysis framework • Cautionary factors • Sample analysis
Definitions • Trend: • to extend in a general direction: follow a general course or veer in a new direction • to show a tendency for example, to incline or trend upwards or to become deflected or shift • Trend analysis: search for patterns over time in order to identify the ways in which they change and develop, veer in new directions, or shift • Incident - Any event that harms security at one or more sites
Analysis Framework • Types of trends • Sources of data • Interpretation of results
Types of Trends • Internal and External patterns • Temporal trends • Spatial trends • Associational trends • Compound trends
Sources of Data • CERT/CC Data • Year 2000 - 21,756 Incidents reported to CERT/CC • Year 2001 (Q1) - 7, 457 Incidents reported to CERT/CC • Profiled 1654 incidents, all active during July 2000 - Feb 2001 (plus some preliminary June data) • Open Source Data: • Web page defacement mirrors • Lexus/Nexus • Full disclosure sites • Social data
Limits of Trending • Inherently partial data • Baseline in dynamic environment • Correlation vs. Causation • Implications • Need to be cautious in kinds of conclusions • Consider strategies for dealing with trends gone wrong
External Pattern: Tool Development Intruder 1 Intruder 2 Analysts
Defenders Intruders Temporal Trend
Analysis Process Incident Information Flow Identify Profiles and Categories Isolate Variables Identify Data Sources Establish Relevancy Identify Gaps
Conclusions • Typifying trends simplifies interpretation • Clarification of goals • Identification of relative importance of characteristics • Understanding cyber security is growing in importance