Supporting Intrusion Detection Work Practice



Journal of Information System Security
Volume 5, Number 2 (2009)
Pages 4273
ISSN 1551-0123
John R. Goodall — Applied Visions, USA
Wayne G. Lutters — University of Maryland, USA
Anita Komlodi — University of Maryland, USA
Information Institute Publishing, Washington DC, USA




In an increasingly networked world, information security is an increasingly important domain, but one that is not well understood. Yet, an understanding of how this work is accomplished is crucial to designing tools and management policies to better support it. The work practice of intrusion detection analysts is a complex fusion of individual and collaborative resource monitoring and problem solving. This paper details the practice of intrusion detection work, specifically highlighting the tasks that make up the work, and it concludes with a discussion of the implications that this work understanding has on future design of tools and organizational policies to make intrusion detection work more efficient.




Work Practice, Intrusion Detection, Computer Network Defense, Task Analysis, Collaboration




