Human Subject Research Protocol: Computer-Aided Human Centric Cyber Situation Awareness: Understanding Cognitive Processes of Cyber Analysts

Abstract

The purpose of this research study is to understand the cognitive process of cyber-security analysts when defending cyber-attacks. Twelve subjects have been recruited from Adelphi Laboratory Center (ALC) of the U.S. Army Research Laboratory (ARL). Each participant is asked to do one or more sessions so that the outcomes can be compared to answer research questions. In the study, subjects play the role of cyber security analysts and are asked to analyze data sources (e.g., network topology and policy, IDS alerts, firewall logs) of the computer network of a large organization to identify suspected attacks, type of attacks, key events or evidence, and associated hypotheses or questions to guide further investigation toward drawing a conclusion. The subjects receive training for the task, complete Pre-Task and Post-Task Questionnaires, and receive no compensation for participating in the study. This research protocol is for continuing the study in collaboration with co-PI s and Associate Investigator of ARL.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Nov 01, 2013
Accession Number
ADA589663

Entities

People

  • John Yen
  • Peng Liu
  • Renee E. Etoty
  • Robert Erbacher
  • William Glodek

Organizations

  • United States Army Research Laboratory

Tags

Communities of Interest

  • Cyber
  • Engineered Resilient Systems

DTIC Thesaurus Topics

  • Cognition
  • Computer Network Security
  • Computer Networks
  • Computers
  • Cyber Defense Techniques
  • Cyberattacks
  • Data Analysis
  • Education
  • Hypotheses
  • Information Science
  • Military Research
  • Network Science
  • Network Topology
  • Networks
  • Psychology
  • Situational Awareness
  • Training

Readers

  • Aerospace Research.
  • Clinical Trial Research.
  • Cybersecurity.

Technology Areas

  • Cyber