Conference paper 2024

An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland Security

Proceedings of the 33rd USENIX Security Symposium
Conference · pp. 2333-2350
Abstract

Cybersecurity is a major challenge for large organizations. Traditional cybersecurity defense is reactive. Cybersecurity operations centers keep out adversaries and incident response teams clean up after break-ins. Recently a proactive stage has been introduced: Cyber Threat Hunting (TH) looks for potential compromises missed by other cyber defenses. TH is mandated for federal executive agencies and government contractors. As threat hunting is a new cybersecurity discipline, most TH teams operate without a defined process. The practices and challenges of TH have not yet been documented. To address this gap, this paper describes the first interview study of threat hunt practitioners. We obtained access and interviewed 11 threat hunters associated with the U.S. government's Department of Homeland Security. Hour-long interviews were conducted. We analyzed the transcripts with process and thematic coding. We describe the diversity among their processes, show that their processes differ from the TH processes reported in the literature, and unify our subjects' descriptions into a single TH process. We enumerate common TH challenges and solutions according to the subjects. The two most common challenges were difficulty in assessing a Threat Hunter's expertise, and developing and maintaining automation. We conclude with recommendations for TH teams (improve planning, focus on automation, and apprentice new members) and highlight directions for future work (finding a TH process that balances flexibility and formalism, and identifying assessments for TH team performance). © USENIX Security Symposium 2024.All rights reserved.

Keywords

Author Keywords

Not provided

Index Keywords

Human resource management Cyber security National security Terrorism Cyber threats Cyber-defense Hunting process Incident response Interview study Large organizations Operation center Third parties US Department of Homeland Security Cyber attacks
Author Affiliations
United States Coast Guard Academy, New London, CT, United States
Purdue University, West Lafayette, IN, United States
Funding & Acknowledgements
No funding information
References 10 References
1 Sawyer, R. Keith, The Cambridge handbook of the learning sciences, second edition, The Cambridge Handbook of the Learning Sciences, Second Edition, pp. 1-776, (2014)
2 Combat Mission Teams and Cyber Protection Teams Lacked Adequate Capabilities and Facilities to Perform Missions, (2015)
3 Gaining the Advantage Applying Cyber Kill Chain Methodology to Network Defense, (2015)
4 Lessons to Learn from the Opm Breach, (2015)
5 Lessons from the Opm Breach, (2016)
6 Cybersecurity Experts Hunting for Hackers, (2017)
7 National Cyber Strategy, (2018)
8 Cost of Cybercrime, (2019)
9 Cost of A Data Breach Report, (2020)
10 Guide to Cyber Threat Hunting, (2020)
Quick Actions
Citation Metrics
6
Times Cited (Scopus)

References 10
Document Identifiers
  • EID 2-s2.0-85204954000
  • Language English