CPC H04L 63/14 (2013.01) | 20 Claims |
1. A computer-implementable method for performing a security operation, comprising:
monitoring an entity, the monitoring observing an electronically-observable data source;
deriving an observable based upon the monitoring of the electronically-observable data source;
identifying a security related activity, the security related activity being based upon the observable from the electronic data source;
analyzing the security related activity, the analyzing the security related activity using a security risk persona and a human-centric factor associated with the entity;
associating the security risk persona with a phase of a cyber kill chain; and,
performing a security operation on the security related activity via a security system, the security operation disrupting performance of the phase of the cyber kill chain, the security operation being performed by at least one of an endpoint device and a security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system executing the security operation on a hardware processor associated with the security analytics system; and wherein
the security risk persona is included within a human-centric risk modeling framework, the human-centric risk modeling framework enabling quantification of the human-centric factor associated with the entity, the human-centric factor comprising a motivation factor, a stressor factor and an organizational dynamics stressor factor, the human-centric factor having an associated effect on the entity, the motivation factor representing a user entity behavior that provides an indication of a motivation for enacting the user entity behavior, the stressor factor representing an issue influencing the user entity behavior, the organizational stressor factor representing an event occurring within an organization affecting the user entity behavior.
|