发表机构
Eindhoven University of Technology(埃因霍温理工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究通过 SuriCap 平台和 CTF 研讨会,分析 60 名参与者生成的 3146 条规则,发现经验对规则质量影响有限,并总结出规则工程的三阶段模式,为 SOC 管理提供改进建议。
AI 中文摘要
许多安全运营中心依赖基于签名的网络入侵检测系统(如 Suricata),但检测规则工程仍未被充分研究。我们通过引入 SuriCap(一个用于规则工程练习的平台)并举办 CTF 风格的研讨会来调查这一过程,60 名参与者(包括受过培训的硕士生和经验丰富的 SOC 专业人员)为四个场景创建了规则。参与者生成了 3146 条有效规则,使我们能够分析他们的方法、性能和迭代模式。令人惊讶的是,先前的经验对规则质量影响有限,这表明经验较少的工程师也能生成与专家相当的规则。我们还观察到规则在可用测试之外的泛化存在挑战,强调了充足标注数据的必要性。通过我们的研究,我们识别出规则工程中的三个阶段和一个常见模式,为 SOC 管理者提供了改进流程和对工程师专业水平预期的见解。
英文摘要
Many Security Operations Centers rely on signature-based Network Intrusion Detection Systems like Suricata, yet detection rule engineering remains understudied. We investigate this process by introducing SuriCap, a platform for rule engineering exercises, and hosting CTF-style workshops where 60 participants, trained MSc students, and experienced SOC professionals, created rules for four scenarios. Participants produced 3146 valid rules, enabling analysis of their methods, performance, and iteration patterns. Surprisingly, prior experience had limited impact on rule quality, suggesting that less experienced engineers can produce rules comparable to experts. We also observed challenges in generalizing rules beyond available tests, underscoring the need for sufficient labeled data. From our study, we identify three phases and a common pattern in rule engineering, offering SOC managers insights to improve their processes and expectations of engineer expertise.