AI 中文总结
本文针对企业网络安全研究的方法选择问题,通过对151篇文献的综述综合,划分11个方法家族并转化为可执行协议,提出受有效性推理约束的方法多元主义及研究人员需遵循的评估设计等结论。
AI 中文摘要
企业网络安全研究采用的方法范围比任何单一社区常规教授的都要广泛。研究人员在面临技术问题之前,首先会遇到选择问题:一项研究可能同时需要系统综述、设计科学 artifact、受控检测实验、访谈研究或攻击图模型。本文通过两种方式解决该问题:首先,对经核实的151篇文献构成的语料库中的方法实践进行叙事综述与综合分析,将这些实践划分为11个方法家族,详细说明每个家族可回答的问题、支撑证据的强度以及常见失效模式;其次,将每个家族转化为可执行协议,包含有序步骤、所需工具、评估标准、常见有效性威胁和报告清单,每个协议还配有可视化映射,以便一目了然地理解序列、决策和威胁。本文还将文献中的矛盾视为证据,例如:不同研究对入侵检测算法的排名存在极大不一致,而这些研究本身均经过严谨设计,本文认为这种模式最简洁的解释是评估设计的差异,而非算法本身的差异,因为这些研究在已知会使结果变化幅度超过算法间差异的设计维度上存在不同。最终,证据支持受明确有效性推理约束的方法多元主义,本文结论为:研究人员必须使评估设计匹配所研究的决策,将技术证据与组织证据进行三角验证,明确说明结果可推广的总体,并报告结果不成立的条件。
英文摘要
Enterprise cybersecurity research draws on a wider range of methods than any single community routinely teaches. Researchers face a selection problem before they face a technical one: a study may simultaneously need a systematic review, a design-science artifact, a controlled detection experiment, an interview study, or an attack-graph model. This paper addresses that problem in two ways. First, it provides a narrative review and synthesis of methodological practices across a verified corpus of 151 works. We organise these practices into eleven methodology families, detailing for each what questions it answers, the strength of its supporting evidence, and its common failure modes. Second, we convert each family into an executable protocol comprising ordered steps, required instruments, evaluation criteria, common validity threats, and a reporting checklist. Every protocol is also visually mapped to make the sequence, decisions, and threats legible at a glance. We also treat contradictions in the literature as evidence. For example, reported rankings of intrusion-detection algorithms are wildly inconsistent across individually careful studies. We argue this pattern is most parsimoniously explained by variations in evaluation design rather than the algorithms themselves, as these studies differ in design dimensions known to shift results by more than the margins separating the algorithms. Ultimately, the evidence supports methodological pluralism disciplined by explicit validity reasoning. We conclude that researchers must match their evaluation design to the decision under study, triangulate technical against organisational evidence, explicitly state the population a result generalises to, and report the conditions under which the result would not hold.
Comments31 pages, 16 figures, 4 tables