ASE 2023
Mon 11 - Fri 15 September 2023 Kirchberg, Luxembourg
Mon 11 Sep 2023 16:10 - 16:30 at Room HU - HCSE-CS Session 2

Analysts in cybersecurity are responsible for monitoring and responding to security incidents in computer systems. They constantly need to acquire sophisticated skills to detect and mitigate sophisticated attacks such as multi-stage and multi-step network attacks (MSNA) that can long hours, days and even months. Unfortunately, there is a lack of MSNA datasets where cybersecurity analyst can train themselves about this matter. Moreover, their inherent complexity makes very difficult to cybersecurity analysts to detect them just reading logs. This work presents a human-centric approach to create MSNAs scenarios for training cybersecurity analysts on detecting concurrent MSNAs. To do this, we have designed NetWars to simulate a training scenario for cybersecurity analyst based on the attacks perpetrated for highly skilled teams during capture The flag events. During the training, cybersecurity analysts receive multiple concurrent MSNAs from 19 different attackers, where the trainee must decide which attack to prioritize for mitigation given that she has limited resources. We hypothesize that using a human-centric cybersecurity approach for cybersecurity analysts learn about detecting and evaluating MSNAs priorities would be better than using traditional approach based on the outputs of Intrusion detection systems. Results are encouraging. the tool’s adoption also yielded a remarkable 95% success rate in generating accurate answers. The usability of the NetWars prototype was highlighted by the users.

Mon 11 Sep

Displayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change

15:30 - 16:30
HCSE-CS Session 2[Workshop] HCSE-CS at Room HU
15:30
20m
Talk
Towards an Understanding of Developers’ Perceptions of Transparency in Software Development: A Preliminary Study
[Workshop] HCSE-CS
Humphrey Obie Monash University, Juliet Ukwella Durham College of Applied Arts & Technology, Kashumi Madampe Monash University, Australia, John Grundy Monash University, Mojtaba Shahin RMIT University, Australia
DOI Media Attached
15:50
20m
Talk
Universal Design for Website Authentication
[Workshop] HCSE-CS
Jacques Ophoff Abertay University, Karen Renaud University of Strathclyde
DOI
16:10
20m
Talk
A human-centric cybersecurity training tool for prioritising MSNAs
[Workshop] HCSE-CS
Vincent Depassier Andrés Bello National University, Romina Torres Adolfo Ibáñez University
DOI