A Novel Team Formation Framework based on Performance in a Cybersecurity Operations Center
A Cybersecurity Operations Center (CSOC) performs various tasks to protect an organization from cyber threats. Several types of personnel collaborate to function effectively as a team to analyze the threat signals, in the form of alerts, arriving from various sources. Teams are often formed ad hoc,...
Gespeichert in:
Veröffentlicht in: | IEEE transactions on services computing 2023-07, Vol.16 (4), p.1-13 |
---|---|
Hauptverfasser: | , , , , |
Format: | Artikel |
Sprache: | eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
container_end_page | 13 |
---|---|
container_issue | 4 |
container_start_page | 1 |
container_title | IEEE transactions on services computing |
container_volume | 16 |
creator | Shah, Ankit Ganesan, Rajesh Jajodia, Sushil Cam, Hasan Hutchinson, Steve |
description | A Cybersecurity Operations Center (CSOC) performs various tasks to protect an organization from cyber threats. Several types of personnel collaborate to function effectively as a team to analyze the threat signals, in the form of alerts, arriving from various sources. Teams are often formed ad hoc, resulting in an imbalance in their performances and thereby increasing the risk associated with the low-performing teams. The current approach taken by behavioral scientists in forming effective teams focuses on first qualitatively assessing individuals such as analysts, who are then grouped into teams based on their credentials and expertise. Our work takes a holistic view of the CSOC by first defining team requirements and then selecting individuals to form several collaborative teams that meet these requirements for every shift of operation. We present a novel team formation framework that integrates optimization, simulation, and scoring methods to form effective teams and introduce a new collaborative score metric that measures their effectiveness. Results from simulated experiments show the formation of effective teams whose collaborative scores are maximized and balanced. Our approach is also able to identify high and low performers within the first few months of implementing the framework. |
doi_str_mv | 10.1109/TSC.2023.3253307 |
format | Article |
fullrecord | <record><control><sourceid>proquest_RIE</sourceid><recordid>TN_cdi_ieee_primary_10061225</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><ieee_id>10061225</ieee_id><sourcerecordid>2847956121</sourcerecordid><originalsourceid>FETCH-LOGICAL-c292t-8a364afa4839efbde9f8f34d2c385e274a26134e55dd39a711f37021196706873</originalsourceid><addsrcrecordid>eNpNkE1LAzEQhoMoWD_uHjwEPG9NMtlNciyLVaFYwXrxEtLdCWzt7tZkq_Tfm9oePA3MPO878BByw9mYc2buF2_lWDABYxA5AFMnZCRAiYwJJk_JiBswGQclz8lFjCvGCqG1GZGPCX3pv3FNF-haOu1D64am7-g0uBZ_-vBJly5iTdPqFYPf37sKadNRR8vdEkPEahuaYUfnGwx_2UhL7AYMV-TMu3XE6-O8JO_Th0X5lM3mj8_lZJZVwogh0w4K6byTGgz6ZY3Gaw-yFhXoHIWSThQcJOZ5XYNxinMPignOTaFYoRVckrtD7yb0X1uMg13129Cll1ZoqUxecMETxQ5UFfoYA3q7CU3rws5yZvcGbTJo9wbt0WCK3B4iDSL-w1kqTMgv2p9rmg</addsrcrecordid><sourcetype>Aggregation Database</sourcetype><iscdi>true</iscdi><recordtype>article</recordtype><pqid>2847956121</pqid></control><display><type>article</type><title>A Novel Team Formation Framework based on Performance in a Cybersecurity Operations Center</title><source>IEEE Electronic Library (IEL)</source><creator>Shah, Ankit ; Ganesan, Rajesh ; Jajodia, Sushil ; Cam, Hasan ; Hutchinson, Steve</creator><creatorcontrib>Shah, Ankit ; Ganesan, Rajesh ; Jajodia, Sushil ; Cam, Hasan ; Hutchinson, Steve</creatorcontrib><description>A Cybersecurity Operations Center (CSOC) performs various tasks to protect an organization from cyber threats. Several types of personnel collaborate to function effectively as a team to analyze the threat signals, in the form of alerts, arriving from various sources. Teams are often formed ad hoc, resulting in an imbalance in their performances and thereby increasing the risk associated with the low-performing teams. The current approach taken by behavioral scientists in forming effective teams focuses on first qualitatively assessing individuals such as analysts, who are then grouped into teams based on their credentials and expertise. Our work takes a holistic view of the CSOC by first defining team requirements and then selecting individuals to form several collaborative teams that meet these requirements for every shift of operation. We present a novel team formation framework that integrates optimization, simulation, and scoring methods to form effective teams and introduce a new collaborative score metric that measures their effectiveness. Results from simulated experiments show the formation of effective teams whose collaborative scores are maximized and balanced. Our approach is also able to identify high and low performers within the first few months of implementing the framework.</description><identifier>ISSN: 1939-1374</identifier><identifier>EISSN: 2372-0204</identifier><identifier>DOI: 10.1109/TSC.2023.3253307</identifier><identifier>CODEN: ITSCAD</identifier><language>eng</language><publisher>Piscataway: IEEE</publisher><subject>Behavioral sciences ; Collaboration ; Combinatorial Optimization ; Computer security ; CSOC Performance ; Cyber Team Formation ; Cybersecurity ; Measurement ; Optimization ; Performance Scoring Model ; Personnel ; Simulation Model ; Task analysis ; Team Collaborative Score ; Teams ; Throughput</subject><ispartof>IEEE transactions on services computing, 2023-07, Vol.16 (4), p.1-13</ispartof><rights>Copyright The Institute of Electrical and Electronics Engineers, Inc. (IEEE) 2023</rights><lds50>peer_reviewed</lds50><woscitedreferencessubscribed>false</woscitedreferencessubscribed><citedby>FETCH-LOGICAL-c292t-8a364afa4839efbde9f8f34d2c385e274a26134e55dd39a711f37021196706873</citedby><cites>FETCH-LOGICAL-c292t-8a364afa4839efbde9f8f34d2c385e274a26134e55dd39a711f37021196706873</cites><orcidid>0000-0003-3210-558X ; 0000-0003-1875-548X ; 0000-0002-8314-6392</orcidid></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><linktohtml>$$Uhttps://ieeexplore.ieee.org/document/10061225$$EHTML$$P50$$Gieee$$H</linktohtml><link.rule.ids>314,776,780,792,27903,27904,54737</link.rule.ids><linktorsrc>$$Uhttps://ieeexplore.ieee.org/document/10061225$$EView_record_in_IEEE$$FView_record_in_$$GIEEE</linktorsrc></links><search><creatorcontrib>Shah, Ankit</creatorcontrib><creatorcontrib>Ganesan, Rajesh</creatorcontrib><creatorcontrib>Jajodia, Sushil</creatorcontrib><creatorcontrib>Cam, Hasan</creatorcontrib><creatorcontrib>Hutchinson, Steve</creatorcontrib><title>A Novel Team Formation Framework based on Performance in a Cybersecurity Operations Center</title><title>IEEE transactions on services computing</title><addtitle>TSC</addtitle><description>A Cybersecurity Operations Center (CSOC) performs various tasks to protect an organization from cyber threats. Several types of personnel collaborate to function effectively as a team to analyze the threat signals, in the form of alerts, arriving from various sources. Teams are often formed ad hoc, resulting in an imbalance in their performances and thereby increasing the risk associated with the low-performing teams. The current approach taken by behavioral scientists in forming effective teams focuses on first qualitatively assessing individuals such as analysts, who are then grouped into teams based on their credentials and expertise. Our work takes a holistic view of the CSOC by first defining team requirements and then selecting individuals to form several collaborative teams that meet these requirements for every shift of operation. We present a novel team formation framework that integrates optimization, simulation, and scoring methods to form effective teams and introduce a new collaborative score metric that measures their effectiveness. Results from simulated experiments show the formation of effective teams whose collaborative scores are maximized and balanced. Our approach is also able to identify high and low performers within the first few months of implementing the framework.</description><subject>Behavioral sciences</subject><subject>Collaboration</subject><subject>Combinatorial Optimization</subject><subject>Computer security</subject><subject>CSOC Performance</subject><subject>Cyber Team Formation</subject><subject>Cybersecurity</subject><subject>Measurement</subject><subject>Optimization</subject><subject>Performance Scoring Model</subject><subject>Personnel</subject><subject>Simulation Model</subject><subject>Task analysis</subject><subject>Team Collaborative Score</subject><subject>Teams</subject><subject>Throughput</subject><issn>1939-1374</issn><issn>2372-0204</issn><fulltext>true</fulltext><rsrctype>article</rsrctype><creationdate>2023</creationdate><recordtype>article</recordtype><sourceid>RIE</sourceid><recordid>eNpNkE1LAzEQhoMoWD_uHjwEPG9NMtlNciyLVaFYwXrxEtLdCWzt7tZkq_Tfm9oePA3MPO878BByw9mYc2buF2_lWDABYxA5AFMnZCRAiYwJJk_JiBswGQclz8lFjCvGCqG1GZGPCX3pv3FNF-haOu1D64am7-g0uBZ_-vBJly5iTdPqFYPf37sKadNRR8vdEkPEahuaYUfnGwx_2UhL7AYMV-TMu3XE6-O8JO_Th0X5lM3mj8_lZJZVwogh0w4K6byTGgz6ZY3Gaw-yFhXoHIWSThQcJOZ5XYNxinMPignOTaFYoRVckrtD7yb0X1uMg13129Cll1ZoqUxecMETxQ5UFfoYA3q7CU3rws5yZvcGbTJo9wbt0WCK3B4iDSL-w1kqTMgv2p9rmg</recordid><startdate>20230701</startdate><enddate>20230701</enddate><creator>Shah, Ankit</creator><creator>Ganesan, Rajesh</creator><creator>Jajodia, Sushil</creator><creator>Cam, Hasan</creator><creator>Hutchinson, Steve</creator><general>IEEE</general><general>The Institute of Electrical and Electronics Engineers, Inc. (IEEE)</general><scope>97E</scope><scope>RIA</scope><scope>RIE</scope><scope>AAYXX</scope><scope>CITATION</scope><scope>7SC</scope><scope>8FD</scope><scope>JQ2</scope><scope>L7M</scope><scope>L~C</scope><scope>L~D</scope><orcidid>https://orcid.org/0000-0003-3210-558X</orcidid><orcidid>https://orcid.org/0000-0003-1875-548X</orcidid><orcidid>https://orcid.org/0000-0002-8314-6392</orcidid></search><sort><creationdate>20230701</creationdate><title>A Novel Team Formation Framework based on Performance in a Cybersecurity Operations Center</title><author>Shah, Ankit ; Ganesan, Rajesh ; Jajodia, Sushil ; Cam, Hasan ; Hutchinson, Steve</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-LOGICAL-c292t-8a364afa4839efbde9f8f34d2c385e274a26134e55dd39a711f37021196706873</frbrgroupid><rsrctype>articles</rsrctype><prefilter>articles</prefilter><language>eng</language><creationdate>2023</creationdate><topic>Behavioral sciences</topic><topic>Collaboration</topic><topic>Combinatorial Optimization</topic><topic>Computer security</topic><topic>CSOC Performance</topic><topic>Cyber Team Formation</topic><topic>Cybersecurity</topic><topic>Measurement</topic><topic>Optimization</topic><topic>Performance Scoring Model</topic><topic>Personnel</topic><topic>Simulation Model</topic><topic>Task analysis</topic><topic>Team Collaborative Score</topic><topic>Teams</topic><topic>Throughput</topic><toplevel>peer_reviewed</toplevel><toplevel>online_resources</toplevel><creatorcontrib>Shah, Ankit</creatorcontrib><creatorcontrib>Ganesan, Rajesh</creatorcontrib><creatorcontrib>Jajodia, Sushil</creatorcontrib><creatorcontrib>Cam, Hasan</creatorcontrib><creatorcontrib>Hutchinson, Steve</creatorcontrib><collection>IEEE All-Society Periodicals Package (ASPP) 2005–Present</collection><collection>IEEE All-Society Periodicals Package (ASPP) 1998–Present</collection><collection>IEEE Electronic Library (IEL)</collection><collection>CrossRef</collection><collection>Computer and Information Systems Abstracts</collection><collection>Technology Research Database</collection><collection>ProQuest Computer Science Collection</collection><collection>Advanced Technologies Database with Aerospace</collection><collection>Computer and Information Systems Abstracts Academic</collection><collection>Computer and Information Systems Abstracts Professional</collection><jtitle>IEEE transactions on services computing</jtitle></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext_linktorsrc</fulltext></delivery><addata><au>Shah, Ankit</au><au>Ganesan, Rajesh</au><au>Jajodia, Sushil</au><au>Cam, Hasan</au><au>Hutchinson, Steve</au><format>journal</format><genre>article</genre><ristype>JOUR</ristype><atitle>A Novel Team Formation Framework based on Performance in a Cybersecurity Operations Center</atitle><jtitle>IEEE transactions on services computing</jtitle><stitle>TSC</stitle><date>2023-07-01</date><risdate>2023</risdate><volume>16</volume><issue>4</issue><spage>1</spage><epage>13</epage><pages>1-13</pages><issn>1939-1374</issn><eissn>2372-0204</eissn><coden>ITSCAD</coden><abstract>A Cybersecurity Operations Center (CSOC) performs various tasks to protect an organization from cyber threats. Several types of personnel collaborate to function effectively as a team to analyze the threat signals, in the form of alerts, arriving from various sources. Teams are often formed ad hoc, resulting in an imbalance in their performances and thereby increasing the risk associated with the low-performing teams. The current approach taken by behavioral scientists in forming effective teams focuses on first qualitatively assessing individuals such as analysts, who are then grouped into teams based on their credentials and expertise. Our work takes a holistic view of the CSOC by first defining team requirements and then selecting individuals to form several collaborative teams that meet these requirements for every shift of operation. We present a novel team formation framework that integrates optimization, simulation, and scoring methods to form effective teams and introduce a new collaborative score metric that measures their effectiveness. Results from simulated experiments show the formation of effective teams whose collaborative scores are maximized and balanced. Our approach is also able to identify high and low performers within the first few months of implementing the framework.</abstract><cop>Piscataway</cop><pub>IEEE</pub><doi>10.1109/TSC.2023.3253307</doi><tpages>13</tpages><orcidid>https://orcid.org/0000-0003-3210-558X</orcidid><orcidid>https://orcid.org/0000-0003-1875-548X</orcidid><orcidid>https://orcid.org/0000-0002-8314-6392</orcidid></addata></record> |
fulltext | fulltext_linktorsrc |
identifier | ISSN: 1939-1374 |
ispartof | IEEE transactions on services computing, 2023-07, Vol.16 (4), p.1-13 |
issn | 1939-1374 2372-0204 |
language | eng |
recordid | cdi_ieee_primary_10061225 |
source | IEEE Electronic Library (IEL) |
subjects | Behavioral sciences Collaboration Combinatorial Optimization Computer security CSOC Performance Cyber Team Formation Cybersecurity Measurement Optimization Performance Scoring Model Personnel Simulation Model Task analysis Team Collaborative Score Teams Throughput |
title | A Novel Team Formation Framework based on Performance in a Cybersecurity Operations Center |
url | https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-01-22T12%3A15%3A03IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-proquest_RIE&rft_val_fmt=info:ofi/fmt:kev:mtx:journal&rft.genre=article&rft.atitle=A%20Novel%20Team%20Formation%20Framework%20based%20on%20Performance%20in%20a%20Cybersecurity%20Operations%20Center&rft.jtitle=IEEE%20transactions%20on%20services%20computing&rft.au=Shah,%20Ankit&rft.date=2023-07-01&rft.volume=16&rft.issue=4&rft.spage=1&rft.epage=13&rft.pages=1-13&rft.issn=1939-1374&rft.eissn=2372-0204&rft.coden=ITSCAD&rft_id=info:doi/10.1109/TSC.2023.3253307&rft_dat=%3Cproquest_RIE%3E2847956121%3C/proquest_RIE%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_pqid=2847956121&rft_id=info:pmid/&rft_ieee_id=10061225&rfr_iscdi=true |