inklap

Comparing the influence of cybersecurity knowledge on attack detection: insights from experts and novice cybersecurity professionals

Mozamel M. Saeed · Open Computer Science · 2024

Abstract This article investigates the effect of cybersecurity knowledge on the ability to detect malicious events in a network. We developed a simplified intrusion detection system (IDS) to simulate real-world scenarios and assess detection capabilities. The IDS features typical network intrusion characteristics, such as signature-based detection and anomaly detection, providing a realistic environment for participants. A cross-sectional study was conducted by recruiting 75 respondents who were from Al Neelain University, with novices observing ten distinct cyber-attack scenarios, including phishing, malware, and denial-of-service attacks. At the same time, experts examined three complex scenarios involving advanced persistent threats and zero-day exploits. Among these participants, 35 were considered novices (students) in cybersecurity, while 40 were security professionals from technical communities. The study procedure involved novices observing ten scenarios and completing a questionnaire assessing their detection accuracy, while experts observed three scenarios and filled out a similar questionnaire. The specific measures used to determine detection capabilities

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً