论文标题

自动化网络安全知识的交流:多案例研究

Automating the Communication of Cybersecurity Knowledge: Multi-Case Study

论文作者

Shojaifar, Alireza, Fricker, Samuel A., Gwerder, Martin

论文摘要

网络安全对于保护公司免受网络威胁至关重要。传统上,网络安全专家评估和提高了公司的能力。但是,许多中小型企业(SMB)认为此类服务不起作用。我们探索一种替代自己动手(DIY)的方法,将网络安全带到中小型企业中。我们的方法和工具CYSEC实现了自决理论(SDT),以指导和激励中小型企业采用良好的网络安全实践。 CYSEC使用评估问题和建议将网络安全知识传达给最终用户中小企业,并鼓励自我激励的变化。在本文中,介绍了CYSEC中SDT的运作,并进行了多案例研究的结果表明,该研究提供了有关中小型企业如何通过CYSEC采用网络安全实践的洞察力。有效的自动网络安全通信取决于SMB的动手技能,工具适应性以及用户愿意记录机密信息。中小型企业想以简单的增量步骤学习,使他们能够理解自己的工作。 SMB提高安全性的动机取决于SMB的业务模型和IT基础架构的评估问题和建议的适用性。这项研究的结果表明,自动咨询可以帮助许多中小型企业采用安全性。最终出版物可通过https://link.springer.com/chapter/10.1007%2F978-3-030-59291-2_8获得。

Cybersecurity is essential for the protection of companies against cyber threats. Traditionally, cybersecurity experts assess and improve a company's capabilities. However, many small and medium-sized businesses (SMBs) consider such services not to be affordable. We explore an alternative do-it-yourself (DIY) approach to bringing cybersecurity to SMBs. Our method and tool, CYSEC, implements the Self-Determination Theory (SDT) to guide and motivate SMBs to adopt good cybersecurity practices. CYSEC uses assessment questions and recommendations to communicate cybersecurity knowledge to the end-user SMBs and encourage self-motivated change. In this paper, the operationalisation of SDT in CYSEC is presented and the results of a multi-case study shown that offer insight into how SMBs adopted cybersecurity practices with CYSEC. Effective automated cybersecurity communication depended on the SMB's hands-on skills, tools adaptedness, and the users' willingness to documenting confidential information. The SMBs wanted to learn in simple, incremental steps, allowing them to understand what they do. An SMB's motivation to improve security depended on the fitness of assessment questions and recommendations with the SMB's business model and IT infrastructure. The results of this study indicate that automated counselling can help many SMBs in security adoption. The final publication is available at Springer via https://link.springer.com/chapter/10.1007%2F978-3-030-59291-2_8

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源