D 2022

SoK: Applications and Challenges of using Recommender Systems in Cybersecurity Incident Handling and Response

HUSÁK, Martin and Milan ČERMÁK

Basic information

Original name

SoK: Applications and Challenges of using Recommender Systems in Cybersecurity Incident Handling and Response

Authors

HUSÁK, Martin (203 Czech Republic, guarantor, belonging to the institution) and Milan ČERMÁK (203 Czech Republic, belonging to the institution)

Edition

Vienna, The 17th International Conference on Availability, Reliability and Security (ARES 2022), p. "25:1"-"25:10", 10 pp. 2022

Publisher

ACM

Other information

Language

English

Type of outcome

Stať ve sborníku

Country of publisher

United States of America

Confidentiality degree

není předmětem státního či obchodního tajemství

Publication form

electronic version available online

References:

URL

RIV identification code

RIV/00216224:14610/22:00126038

Organization

Ústav výpočetní techniky – Repository – Repository

ISBN

978-1-4503-9670-7

DOI

http://dx.doi.org/10.1145/3538969.3538981

UT WoS

001122620500025

Keywords in English

Recommender System;Incident Handling;Incident Response

Links

EF16_019/0000822, research and development project.
Změněno: 28/6/2024 04:39, RNDr. Daniel Jakubík

Abstract

V originále

Incident handling, a fundamental activity of a cybersecurity incident response team, is a complex discipline that consumes a significant amount of personnel's time and costs. There are continuous efforts to facilitate incident handling and response in terms of providing procedural or decision support and processing relevant data. In this paper, we survey the approaches towards (semi-)automated incident handling and response backed by recommender systems that are successful in other domains. We discuss which phases and tiers of incident handling can be automated and to what level while evaluating the maturity of proposed approaches and tools. While we did not find a full-scale recommender system that would guide the user through incident handling and suggest which steps to take, many of them aim at particular problems. The discussed issues are not resolved yet but seem to get the attention of researchers and will likely be investigated in the future.
Displayed: 1/11/2024 07:18