论文标题
多样性在网络安全风险分析中的作用:实验计划
The Role of Diversity in Cybersecurity Risk Analysis: An Experimental Plan
论文作者
论文摘要
网络安全威胁和风险分析(RA)方法用于识别和减轻软件开发生命周期中的安全风险。现有方法仅自动化分析程序的一部分,在识别,可行性和风险分析以及质量评估中留下关键决策,以由专家判断确定。因此,在实践中,专家团队通过举办头脑风暴研讨会来手动分析系统设计。这类决定是面对不确定性的,留出了偏见的判断空间(例如,专家类别的优惠待遇)。分析过程中的偏见决策可能会导致专业知识的不平等贡献,特别是因为在安全团队中,某些多样性维度(即性别)的代表性不足。除了对非技术威胁的风险感知的工作外,现有的工作还没有经验研究多样性在技术人工制品的风险分析中的作用。本文提出了一个实验计划,以识别RA中的关键多样性因素。
Cybersecurity threat and risk analysis (RA) approaches are used to identify and mitigate security risks early-on in the software development life-cycle. Existing approaches automate only parts of the analysis procedure, leaving key decisions in identification, feasibility and risk analysis, and quality assessment to be determined by expert judgement. Therefore, in practice teams of experts manually analyze the system design by holding brainstorming workshops. Such decisions are made in face of uncertainties, leaving room for biased judgement (e.g., preferential treatment of category of experts). Biased decision making during the analysis may result in unequal contribution of expertise, particularly since some diversity dimensions (i.e., gender) are underrepresented in security teams. Beyond the work of risk perception of non-technical threats, no existing work has empirically studied the role of diversity in the risk analysis of technical artefacts. This paper proposes an experimental plan for identifying the key diversity factors in RA.