• DocumentCode
    263557
  • Title

    Beyond technical data - a more comprehensive situational awareness fed by available intelligence information

  • Author

    Kornmaier, Andreas ; Jaouen, Fabrice

  • Author_Institution
    Fac. of Comput. Sci., Univ. der Bundeswehr Munchen, Neubiberg, Germany
  • fYear
    2014
  • fDate
    3-6 June 2014
  • Firstpage
    139
  • Lastpage
    154
  • Abstract
    Information on cyber incidents and threats are currently collected and processed with a strong technical focus. Threat and vulnerability information alone are not a solid base for effective, affordable or actionable security advice for decision makers. They need more than a small technical cut of a bigger situational picture to combat and not only to mitigate the cyber threat. We first give a short overview over the related work that can be found in the literature. We found that the approaches mostly analysed “what” has been done, instead of looking more generically beyond the technical aspects for the tactics, techniques and procedures to identify the “how” it was done, by whom and why. We examine then, what information categories and data already exist to answer the question for an adversary´s capabilities and objectives. As traditional intelligence tries to serve a better understanding of adversaries´ capabilities, actions, and intent, the same is feasible in the cyber space with cyber intelligence. Thus, we identify information sources in the military and civil environment, before we propose to link that traditional information with the technical data for a better situational picture. We give examples of information that can be collected from traditional intelligence for correlation with technical data. Thus, the same intelligence operational picture for the cyber sphere could be developed like the one that is traditionally fed from conventional intelligence disciplines. Finally we propose a way of including intelligence processing in cyber analysis. We finally outline requirements that are key for a successful exchange of information and intelligence between military/civil information providers.
  • Keywords
    decision making; information resources; security of data; adversary capabilities; civil environment; civil information providers; cyber analysis; cyber incidents; cyber intelligence; cyber space; cyber threats; decision makers; information categories; information sources; intelligence information; intelligence processing; military environment; military information providers; situational awareness; technical data; threat information; vulnerability information; Bibliographies; Charge coupled devices; Context; Decision making; Malware; Solids; cyber; cyber intelligence; information collection fusion; intelligence;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cyber Conflict (CyCon 2014), 2014 6th International Conference On
  • Conference_Location
    Tallinn
  • ISSN
    2325-5366
  • Print_ISBN
    978-9949-9544-0-7
  • Type

    conf

  • DOI
    10.1109/CYCON.2014.6916400
  • Filename
    6916400