I know my network: collaboration and expertise in intrusion detection

  • Authors:
  • John R. Goodall;Wayne G. Lutters;Anita Komlodi

  • Affiliations:
  • UMBC, Baltimore, MD;UMBC, Baltimore, MD;UMBC, Baltimore, MD

  • Venue:
  • CSCW '04 Proceedings of the 2004 ACM conference on Computer supported cooperative work
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

The work of intrusion detection (ID) in accomplishing network security is complex, requiring highly sought-after expertise. While limited automation exists, the role of human ID analysts remains crucial. This paper presents the results of an exploratory field study examining the role of expertise and collaboration in ID work. Through an analysis of the common and situated expertise required in ID work, our results counter basic assumptions about its individualistic character, revealing significant distributed collaboration. Current ID support tools provide no support for this collaborative problem solving. The results of this research highlight ID as an engaging CSCW work domain, one rich with organizational insights, design challenges, and practical import.