On Collaboration and Automation in the Context of Threat Detection and Response with Privacy-Preserving Features
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F63839172%3A_____%2F25%3A10133794" target="_blank" >RIV/63839172:_____/25:10133794 - isvavai.cz</a>
Nalezeny alternativní kódy
RIV/00216224:14610/25:00140657
Výsledek na webu
<a href="https://doi.org/10.1145/3707651" target="_blank" >https://doi.org/10.1145/3707651</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1145/3707651" target="_blank" >10.1145/3707651</a>
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
On Collaboration and Automation in the Context of Threat Detection and Response with Privacy-Preserving Features
Popis výsledku v původním jazyce
Organizations and their security operation centers often struggle to detect and respond effectively to an extensive quantity of ever-evolving cyberattacks. While collaboration, such as threat intelligence sharing between security teams, and response automation are often discussed in the cybersecurity community, issues like data sensitivity and confidence in detection may hinder their adoption. This work investigates the potentials and challenges of collaboration and automation to enhance incident response processes. We propose a reference architecture for data sharing in threat detection and response, aiming to boost collaborative and automated efforts across organizations while also considering privacy-preserving features. To address these challenges and potentials, we discuss how such a framework could enhance current response processes within and between organizations, validated with results in local attack detection, incident response, and data sharing.
Název v anglickém jazyce
On Collaboration and Automation in the Context of Threat Detection and Response with Privacy-Preserving Features
Popis výsledku anglicky
Organizations and their security operation centers often struggle to detect and respond effectively to an extensive quantity of ever-evolving cyberattacks. While collaboration, such as threat intelligence sharing between security teams, and response automation are often discussed in the cybersecurity community, issues like data sensitivity and confidence in detection may hinder their adoption. This work investigates the potentials and challenges of collaboration and automation to enhance incident response processes. We propose a reference architecture for data sharing in threat detection and response, aiming to boost collaborative and automated efforts across organizations while also considering privacy-preserving features. To address these challenges and potentials, we discuss how such a framework could enhance current response processes within and between organizations, validated with results in local attack detection, incident response, and data sharing.
Klasifikace
Druh
J<sub>imp</sub> - Článek v periodiku v databázi Web of Science
CEP obor
—
OECD FORD obor
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Návaznosti výsledku
Projekt
<a href="/cs/project/LM2023054" target="_blank" >LM2023054: e-Infrastruktura CZ</a><br>
Návaznosti
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Název periodika
DIGITAL THREATS: RESEARCH AND PRACTICE
ISSN
2692-1626
e-ISSN
2576-5337
Svazek periodika
6
Číslo periodika v rámci svazku
1
Stát vydavatele periodika
US - Spojené státy americké
Počet stran výsledku
36
Strana od-do
5
Kód UT WoS článku
001470073800003
EID výsledku v databázi Scopus
2-s2.0-105002995143