Cybersecurity increasingly relies on threat hunters to proactively identify adversarial activity, yet the cognitive work underlying threat hunting remains underexplored or insufficiently supported by existing tools. Building on prior studies that examined how threat hunters construct and share mental models during investigations, we derived a set of design propositions to support their cognitive and collaborative work. In this paper, we present the Threat Hunter Board, a prototype tool that operationalizes these design propositions by enabling threat hunters to externalize reasoning, organize investigative leads, and maintain continuity across sessions. Using a design science paradigm, we describe the solution design rationale and artifact development. In addition, we propose six design heuristics that form a solution-evaluation framework for assessing cognitive support in threat hunting tools. An initial evaluation using a cognitive walkthrough provides early evidence of feasibility, while future work will focus on user-based validation with professional threat hunters.
翻译:网络安全日益依赖威胁猎手主动识别对抗性活动,然而威胁猎杀背后的认知工作仍未得到充分探索,现有工具也未能提供足够支持。基于先前研究中对威胁猎手在调查过程中如何构建和共享心智模型的考察,我们提出了一套支持其认知与协作工作的设计主张。本文介绍Threat Hunter Board原型工具,该工具通过使威胁猎手能够外化推理过程、组织调查线索并保持跨会话连续性,实现了这些设计主张的可操作化。采用设计科学研究范式,我们阐述了解决方案的设计原理与工件开发过程。此外,我们提出六项设计启发式原则,构成评估威胁猎杀工具认知支持能力的解决方案评估框架。通过认知走查法进行的初步评估提供了可行性的早期证据,后续工作将聚焦于与专业威胁猎手的用户验证研究。