There is a perceived disconnect between how ad hoc industry solutions and academic research solutions in cyber security are developed and applied. Is there a difference in philosophy in how solutions to cyber security problems are developed by industry and by academia. What could academia and industry do to bridge this gap and speed up the development and use of effective cybersecurity solutions? This paper provides an overview of the most critical gaps and solutions identified by an interdisciplinary expert exchange on the topic. The discussion was held in the form of the webinar "Bridging the Bubbles: Connecting Academia and Industry in Cybersecurity Research" in November 2022 as part of the Rogers Cybersecure Catalyst webinar series. Panelists included researchers from academia and industry as well as experts from industry and business development. The key findings and recommendations of this exchange are supported by the relevant scientific literature on the topic within this paper. Different approaches and time frames in development and lifecycle management, challenges in knowledge transfer and communication as well as heterogeneous metrics for success in projects are examples of the evaluated subject areas.
翻译:学术界与产业界在网络安全领域的临时解决方案与学术研究解决方案的开发与应用之间存在明显的脱节。产业界和学术界在解决网络安全问题时,其方法论是否存在哲学差异?学术界与产业界应如何弥合这一鸿沟,加速有效网络安全解决方案的开发与应用?本文从跨学科专家交流的角度,概述了该议题中最关键的差距与解决方案。该讨论以2022年11月举办的"连接气泡:网络安全研究中的学术界与产业界合作"网络研讨会形式进行,作为Rogers Cybersecure Catalyst系列网络研讨会的一部分。小组讨论成员包括来自学术界和产业界的研究人员,以及产业界和商业发展领域的专家。本次交流的主要发现与建议得到了本文中相关科学文献的支持。评估的主题领域包括:开发与生命周期管理中不同的方法与时间框架、知识转移与沟通中的挑战,以及项目成功的异质性衡量标准等。