论文标题
基础率谬论REDUX和网络安全的深入潜水审查
Base-Rate Fallacy Redux and a Deep Dive Review in Cybersecurity
论文作者
论文摘要
本文研究了科学基础网络安全研究的现状,重点是基于非签名的入侵检测领域。首先,该论文重新检查了Axelsson最初发表的基本利率谬论,将误报的影响置于上下文中。鉴于误报的相对数量很高,本文主张对假阳性的更深入分析,类似于对真实阳性的分析。本文的第二部分研究了用于分析非签名入侵检测技术的指标,当前的指标的现状以及现状对科学进步的影响。最后,本文分析了在线攻击图及其适用性的使用,尤其是在受限环境(例如物联网设备)的情况下。还检查了在这种约束环境中使用离线攻击图的使用。本质上,深入的潜水审查确定了整个领域的多个领域,在这些领域中,科学方法的有效性和有效性可以大大改善,例如,通过删除逻辑谬论。
This paper examines the current state of the science underlying cybersecurity research with an emphasis on the non-signature-based intrusion detection domain. First, the paper re-examines the base-rate fallacy originally published by Axelsson, putting the impact of false positives into context. Given the relative high numbers of false positives, the paper argues for deeper analysis of false positives, akin to the analysis that true positives are treated to. The second section of the paper examines the metrics being used to analyze non-signature intrusion detection techniques, the current status quo of employed metrics, and the impact of the status quo on scientific advancement. Finally, the paper analyzes the use of online attack graphs and their applicability, especially in scenarios of constrained environments, such as Internet of Things devices. The use of offline attack graphs in such constrained environments is also examined. In essence, a deep dive review identified multiple areas throughout the field in which the effectiveness and validity of the scientific method can be greatly improved, e.g., through removal of logical fallacies.