The development of technology across multiple sectors and the growing importance of cyber warfare make the development of Cyber Situational Awareness (CSA) a fundamental component of any cyber defense strategy. CSA, as a practice, enables understanding of the current landscape within an organization or critical infrastructure, anticipating potential threats, and responding appropriately to cyber risks. With CSA, we are not simply seeking a passive point of view, but rather informed decision-making that allows us to improve response times and monitor the consequences and effects an attack has on one of our elements and how it will affect other elements it interacts with. In this paper, we review 5 CSA platforms, seeking differentiating characteristics between each proposal and outlining 6 proposed criteria that can be applied when creating a military smart CSA platform. To this end, we have validated the proposed criteria in CRUSOE, an open-source CSA platform developed by CSIRT-MU. After applying some modifications and experiments, it turned out to be applicable to this field.
翻译:跨多个领域的技术发展以及网络战日益增长的重要性,使得网络态势感知(CSA)的开发成为任何网络防御战略的基本组成部分。作为一种实践,CSA能够理解组织或关键基础设施内的当前态势,预测潜在威胁,并适当应对网络风险。借助CSA,我们不仅寻求被动的视角,更追求基于信息的决策,以缩短响应时间,并监控攻击对我们某个要素的影响及其对相关交互要素的连锁效应。本文回顾了5种CSA平台,探讨了各方案间的差异化特征,并提出了6项可用于构建军事智能CSA平台的标准。为此,我们在CRUSOE(由CSIRT-MU开发的开源CSA平台)中验证了所提标准。经过若干修改和实验,证明该标准适用于此领域。