HCCRSep 3, 2020

Exploratory Analysis of File System Metadata for Rapid Investigation of Security Incidents

arXiv:2009.01698v26 citations
Originality Synthesis-oriented
AI Analysis

This addresses the need for more accessible and efficient security analysis tools for cybersecurity analysts, though it appears incremental as it builds on existing techniques.

The paper tackled the problem of inefficient and expert-dependent cybersecurity incident investigation by proposing an approach to analyze disk snapshots more efficiently with lower expert demands, validated through evaluation with security teams.

Investigating cybersecurity incidents requires in-depth knowledge from the analyst. Moreover, the whole process is demanding due to the vast data volumes that need to be analyzed. While various techniques exist nowadays to help with particular tasks of the analysis, the process as a whole still requires a lot of manual activities and expert skills. We propose an approach that allows the analysis of disk snapshots more efficiently and with lower demands on expert knowledge. Following a user-centered design methodology, we implemented an analytical tool to guide analysts during security incident investigations. The viability of the solution was validated by an evaluation conducted with members of different security teams.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes