Author_Institution :
E-Security Group, Intell. & Security Assurance, London, UK
Abstract :
The underpinning of situational awareness in computer networks is to identify adversaries, estimate impact of attacks, evaluate risks, understand situations and make sound decisions on how to protect valued assets swiftly and accurately. SA also underscores situation assessment in order to make accurate forecast in dynamic and complex environments. In this paper, situational awareness in computer network security is investigated. Functional attributes of situational awareness in computer network security are discussed: dynamism and complexity, automation, realtime processing, multisource data fusion, heterogeneity, security visualisation, decision control, risk assessment, resolution, forecasting and prediction.
Keywords :
computer networks; security of data; computer network security; decision control; multisource data fusion; risk assessment; security visualisation; situational awareness; valued assets protection; Aggregates; Automation; Computer networks; Computer security; Data security; Data visualization; Information security; Intrusion detection; Monitoring; Protection; Computer Network Defence; NSSA requirements; Network Security; Situational Awareness;