Data Collection and Research in CDXs: Command and Control, Cyber Situational Awareness and Intelligence Perspectives on Cyber Defense
2019 (English) In: 24th International Command and Control Research and Technology Symposium (ICCRTS): Cyber Risk to Mission / [ed] Alberts, David, International Command and Control Institute , 2019, Vol. Topic 9, article id 24Conference paper, Published paper (Refereed)
Abstract [en]
The annual cyber defense exercise Locked Shields is the world’s largest unclassified defensive exercise. The exercise participants form “blue teams” that are tasked to defend their critical infrastructure against an attacking “red team.” The blue teams are scored based on how well they keep their essential system functions running and the extent to which they manage to assess and report what they are exposed to. During Locked Shields 2019, 24 blue teams from 30 countries participated in a two-day exercise. The case study presented in this paper focuses on one of the blue teams. The team consisted of around 60 people from governmental institutions as well as private companies. The objective of this paper is to explore the possibilities to collect meaningful data for research on Command and Control, C2, Cyber Situational Awareness, CSA, and Intelligence in conjunction with an inter-organizational cyber defense team during a cyber defense exercise. During preparations preceding the exercise, the research team observed the development of strategy, coordination structures and organization in the temporarily formed team as it prepared to solve the highly challenging exercise tasks. During the exercise, data collection included questionnaires, observations, team communication logs, reporting from the blue to the white team and performance scores. The data collection sought to satisfy needs within three research themes - 1) command and control, C2, 2) cyber situational awareness, and 3) intelligence. A review of the dataset showed that the data is well suited for further analysis. The paper presents initial results as well as an outline of how the different types of data collected contribute to research within the three research themes.
Place, publisher, year, edition, pages International Command and Control Institute , 2019. Vol. Topic 9, article id 24
Series
International Command and Control Research and Technology Symposium (ICCRTS) proceedings, E-ISSN 2577-1604
Keywords [en]
data collection, command and control, cyber situational awareness, intelligence, cyberspace operations
National Category
Other Social Sciences not elsewhere specified
Research subject Systems science for defence and security
Identifiers URN: urn:nbn:se:fhs:diva-8813 OAI: oai:DiVA.org:fhs-8813 DiVA, id: diva2:1369835
Conference 24th International Command and Control Research and Technology Symposium (ICCRTS), 29-31 October, Laurel, USA
2019-11-132019-11-132022-01-14 Bibliographically approved