As cyber systems become increasingly complex and cybersecurity threats become more prominent, defenders must prepare, coordinate, automate, document, and share their response methodologies to the extent possible. The CACAO standard was developed to satisfy the above requirements providing a common machine-readable framework and schema to document cybersecurity operations processes, including defensive tradecraft and tactics, techniques, and procedures. Although this approach is compelling, a remaining limitation is that CACAO provides no native modeling notation for graphically representing playbooks, which is crucial for simplifying their creation, modification, and understanding. In contrast, the industry is familiar with BPMN, a standards-based modeling notation for business processes that has also found its place in representing cybersecurity processes. This research examines BPMN and CACAO and explores the feasibility of using the BPMN modeling notation to graphically represent CACAO security playbooks. The results indicate that mapping CACAO and BPMN is attainable at an abstract level; however, conversion from one encoding to another introduces a degree of complexity due to the multiple ways CACAO constructs can be represented in BPMN and the extensions required in BPMN to fully support CACAO.
翻译:随着网络系统日益复杂,网络安全威胁愈发突出,防御者必须尽可能准备、协调、自动化、记录和共享其响应方法。CACAO标准旨在满足上述需求,提供了一个通用的机器可读框架和模式,用以记录网络安全操作流程,包括防御性技艺及战术、技术和程序。尽管这种方法颇具吸引力,但其局限在于CACAO未提供用于图形化表示剧本的原生建模符号,而这对于简化剧本的创建、修改和理解至关重要。相比之下,业界熟悉BPMN——一种基于标准的业务流程建模符号,它同样在网络安全流程表示中找到了应用。本研究对BPMN和CACAO进行了分析,探讨了使用BPMN建模符号图形化表示CACAO安全剧本的可行性。结果表明,在抽象层面上实现CACAO与BPMN的映射是可行的;然而,由于CACAO结构在BPMN中的多种表示方式以及BPMN为完全支持CACAO所需进行的扩展,从一种编码转换为另一种编码会引入一定程度的复杂性。