Abstract: Improved Security Detection & Response Via Optimized Alert Output - A Usability Study

Cut the noise, hone the signal

Once in a while, you get shown the light in the strangest of places if you look at it right ~Garcia/Hunter

I’ve been absent here for many months, but it has been with purpose. My dissertation, Improved Security Detection & Response via Optimized Alert Output: A Usability Study, is complete, and I’ve successfully defended it; pursuit of my PhD is complete, a new journey begins. I’ll begin with posting the abstract here. I’m in the midst of the dissertation publishing process, but once ready, it will be available in a fully open source capacity, no paywalls or subscription required. I’ll also share all the data (fully anonymized) as well as statistical routines and analysis in R. I’ll continue to post the related artifacts, including to full dissertation in via the R bookdown and thesisdown packages. I look forward to sharing this research with you while discussing it in a variety of forums and extending it to additional research opportunities. Stay tuned here for more.

[Read More]

Security Detection and Response Alert Output Usability Survey

Scenario-based Research for Cybersecurity Analysts and Managers

As a PhD candidate at Capitol Technology University I’m conducting a scenario-based security detection & response alert output usability survey for cybersecurity analysts and managers in Security Operation Center (SOC), Digital Forensic and Incident Response (DFIR), Detection and Response Team (DART) & Threat Intelligence (TI) roles. These roles often make use of output from detection methods including machine learning & data science. Individual contributors & managers alike are welcome.
The purpose of the research is to determine if there is a statistically significant difference in security analysts’ preference and acceptance between text alert output (TAO) and visual alert output (VAO) derived by these methods.
The survey should take 20 minutes.
https://www.surveymonkey.com/r/TAOvsVAO

[Read More]
SOC  Blue Team  DFIR  DART  Survey  TI