Towards Understanding Diagnostic Work During the Detection and Investigation of Security Incidents. Werlinger, R., Muldner, K., Hawkey, K., & Beznosov, K. In HAISA, pages 119–134, 2009.
Paper abstract bibtex This study investigates how security practitioners perform diagnostic work during the identification of security incidents. Based on empirical data from 16 interviews with security practitioners, we identify the tasks, skills, strategies and tools that security practitioners use to diagnose security incidents. Our analysis shows that diagnosis is a highly collaborative activity, which may involve practitioners developing their own tools to perform specific tasks. Our results also show that diagnosis during incident response is complicated by practitioners’ need to rely on tacit knowledge, as well as usability issues with security tools. We offer recommendations to improve technology that supports the diagnosis of security incidents.
@InProceedings{werlinger2009towards,
author = {Werlinger, Rodrigo and Muldner, Kasia and Hawkey, Kirstie and Beznosov, Konstantin},
booktitle = {HAISA},
title = {{T}owards {U}nderstanding {D}iagnostic {W}ork {D}uring the {D}etection and {I}nvestigation of {S}ecurity {I}ncidents.},
year = {2009},
pages = {119--134},
abstract = {This study investigates how security practitioners perform diagnostic work during the identification of security incidents. Based on empirical data from 16 interviews with security practitioners, we identify the tasks, skills, strategies and tools that security practitioners use to diagnose security incidents. Our analysis shows that diagnosis is a highly collaborative activity, which may involve practitioners developing their own tools to perform specific tasks. Our results also show that diagnosis during incident response is complicated by practitioners’ need to rely on tacit knowledge, as well as usability issues with security tools. We offer recommendations to improve technology that supports the diagnosis of security incidents.},
url = {https://drive.google.com/file/d/1JPsVffj713vbHiLXcaFjqRIgd2zzJtph/view?usp=drive_link},
}
Downloads: 0
{"_id":"KbfKFftBBCNTXXFAk","bibbaseid":"werlinger-muldner-hawkey-beznosov-towardsunderstandingdiagnosticworkduringthedetectionandinvestigationofsecurityincidents-2009","author_short":["Werlinger, R.","Muldner, K.","Hawkey, K.","Beznosov, K."],"bibdata":{"bibtype":"inproceedings","type":"inproceedings","author":[{"propositions":[],"lastnames":["Werlinger"],"firstnames":["Rodrigo"],"suffixes":[]},{"propositions":[],"lastnames":["Muldner"],"firstnames":["Kasia"],"suffixes":[]},{"propositions":[],"lastnames":["Hawkey"],"firstnames":["Kirstie"],"suffixes":[]},{"propositions":[],"lastnames":["Beznosov"],"firstnames":["Konstantin"],"suffixes":[]}],"booktitle":"HAISA","title":"Towards Understanding Diagnostic Work During the Detection and Investigation of Security Incidents.","year":"2009","pages":"119–134","abstract":"This study investigates how security practitioners perform diagnostic work during the identification of security incidents. Based on empirical data from 16 interviews with security practitioners, we identify the tasks, skills, strategies and tools that security practitioners use to diagnose security incidents. Our analysis shows that diagnosis is a highly collaborative activity, which may involve practitioners developing their own tools to perform specific tasks. Our results also show that diagnosis during incident response is complicated by practitioners’ need to rely on tacit knowledge, as well as usability issues with security tools. We offer recommendations to improve technology that supports the diagnosis of security incidents.","url":"https://drive.google.com/file/d/1JPsVffj713vbHiLXcaFjqRIgd2zzJtph/view?usp=drive_link","bibtex":"@InProceedings{werlinger2009towards,\n author = {Werlinger, Rodrigo and Muldner, Kasia and Hawkey, Kirstie and Beznosov, Konstantin},\n booktitle = {HAISA},\n title = {{T}owards {U}nderstanding {D}iagnostic {W}ork {D}uring the {D}etection and {I}nvestigation of {S}ecurity {I}ncidents.},\n year = {2009},\n pages = {119--134},\n abstract = {This study investigates how security practitioners perform diagnostic work during the identification of security incidents. Based on empirical data from 16 interviews with security practitioners, we identify the tasks, skills, strategies and tools that security practitioners use to diagnose security incidents. Our analysis shows that diagnosis is a highly collaborative activity, which may involve practitioners developing their own tools to perform specific tasks. Our results also show that diagnosis during incident response is complicated by practitioners’ need to rely on tacit knowledge, as well as usability issues with security tools. We offer recommendations to improve technology that supports the diagnosis of security incidents.},\n url = {https://drive.google.com/file/d/1JPsVffj713vbHiLXcaFjqRIgd2zzJtph/view?usp=drive_link},\n}\n\n","author_short":["Werlinger, R.","Muldner, K.","Hawkey, K.","Beznosov, K."],"key":"werlinger2009towards","id":"werlinger2009towards","bibbaseid":"werlinger-muldner-hawkey-beznosov-towardsunderstandingdiagnosticworkduringthedetectionandinvestigationofsecurityincidents-2009","role":"author","urls":{"Paper":"https://drive.google.com/file/d/1JPsVffj713vbHiLXcaFjqRIgd2zzJtph/view?usp=drive_link"},"metadata":{"authorlinks":{}}},"bibtype":"inproceedings","biburl":"https://bibbase.org/f/i3hTAQ2wxvvLpcpZu/lersse_publications.bib","dataSources":["gdEygGa34uWkjynDQ","ikcgcNLWkPYd7asYj","WjyYKjDEeDNZ5D7kg","YAZ3EPKt9iuMHML8Y","Z66AwpjqbyDaCRuAz","vzLiYoozjbMtpq3bv","yyg88BndAbrgER4pG","qxYmJrWKptQFZpZn2","uXASf7FkwMkTdi7XQ","L3Q9QEq5gEyYsbhX8","PCm8nFZLWR38NRiRu","jagWcnNcoBLvejBcm","8cHa97bWQybuQhHDo","Kx35bmNmuB9SWebed","M5QirAZCjcxYLMFLM","BpNnApTKxApG4JxkD","BuaeMqxTDRXAZtmNe","r8QoBNxamnpCZ3Dwb","gKAKkjtPkN44YFKMk","nDjRsp2dBrEbdKR78","Raz2SaaZA89irapRN","ZnaQsM7NDPZR4BFeb"],"keywords":[],"search_terms":["towards","understanding","diagnostic","work","during","detection","investigation","security","incidents","werlinger","muldner","hawkey","beznosov"],"title":"Towards Understanding Diagnostic Work During the Detection and Investigation of Security Incidents.","year":2009}