Organizations use intrusion detection systems (IDSes) to identify harmful activity among millions of computer network events. Cybersecurity analysts review IDS alarms to verify whether malicious activity occurred and to take remedial action. However, IDS systems exhibit high false alarm rates. This study examines the impact of IDS false alarm rate on human analyst sensitivity (probability of detection), precision (positive predictive value), and time on task when evaluating IDS alarms. A controlled experiment was conducted with participants divided into two treatment groups, 50% IDS false alarm rate and 86% false alarm rate, who classified whether simulated IDS alarms were true or false alarms. Results show statistically significant differences in precision and time on task. The median values for the 86% false alarm rate group were 47% lower precision and 40% slower time on task than the 50% false alarm rate group. No significant difference in analyst sensitivity was observed.
翻译:组织使用入侵检测系统(IDS)从数百万网络事件中识别有害活动。网络安全分析师审查IDS告警以确认是否存在恶意行为并采取补救措施。然而,IDS系统存在高误报率。本研究探讨了IDS误报率对分析师评估告警时的灵敏度(检测概率)、精准度(阳性预测值)及任务耗时的影响。我们开展了一项受控实验,将参与者分为两个处理组(50%误报率组与86%误报率组),要求其对模拟IDS告警的真实性进行判定。结果表明,在精准度和任务耗时方面存在统计学显著差异。与50%误报率组相比,86%误报率组的中位精准度降低47%,任务耗时增加40%。未观察到分析师灵敏度的显著差异。