An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland Security
William P. Maxam III, James C. Davis
摘要
Cybersecurity is a major challenge for large organizations. Traditional cybersecurity defense is reactive. Cybersecurity operations centers keep out adversaries and incident response teams clean up after break-ins. Recently a proactive stage has been introduced: Cyber Threat Hunting (TH) looks for potential compromises missed by other cyber defenses. TH is mandated for federal executive agencies and government contractors. As threat hunting is a new cybersecurity discipline, most TH teams operate without a defined process. The practices and challenges of TH have not yet been documented. To address this gap, this paper describes the first interview study of threat hunt practitioners. We obtained access and interviewed 11 threat hunters associated with the U.S. government's Department of Homeland Security. Hour-long interviews were conducted. We analyzed the transcripts with process and thematic coding.We describe the diversity among their processes, show that their processes differ from the TH processes reported in the literature, and unify our subjects' descriptions into a single TH process.We enumerate common TH challenges and solutions according to the subjects. The two most common challenges were difficulty in assessing a Threat Hunter's expertise, and developing and maintaining automation. We conclude with recommendations for TH teams (improve planning, focus on automation, and apprentice new members) and highlight directions for future work (finding a TH process that balances flexibility and formalism, and identifying assessments for TH team performance).
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of SigstoreKelechi G. Kalu, Sofia Okorafor, Tanmay Singla, Sophie Chen 等USENIX Security 2026 · 被引用 3 次
- An Industry Interview Study of Software Signing for Supply Chain SecurityKelechi G. Kalu, Tanmay Singla, Chinenye Okafor, Santiago Torres-Arias 等USENIX Security 2025
- Expert Insights into Advanced Persistent Threats: Analysis, Attribution, and ChallengesAakanksha Saha, James Mattei, Jorge Blasco, Lorenzo Cavallaro 等USENIX Security 2025
- Learning From Software Failures: A Case Study at a National Space Research CenterDharun Anandayuvaraj, Tanmay Singla, Zain Alabedin Haj Hammadeh, Andreas Lund 等ICSE 2026
- Batten the Hatches: Cybersecurity with Military MarinersRyan Von Brock, Anna Raymaker, Animesh Chhotaray, Frank Li 等CCS 2026
它引用的顶会 Paper5
- POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat HuntingSadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2019 · 被引用 313 次
- Enabling Efficient Cyber Threat Hunting With Cyber Threat IntelligencePeng Gao, Fei Shao, Xiaoyuan Liu, Xusheng Xiao 等ICDE 2021 · 被引用 124 次
- The Industrial Age of HackingTimothy Nosco, Jared Ziegler, Zechariah Clark, Davy Marrero 等USENIX Security 2020
- Vulnerability Discovery for All: Experiences of Marginalization in Vulnerability DiscoveryKelsey R. Fulton, Samantha Katcher, Kevin Song, Marshini Chetty 等S&P 2023
- Investigating the Password Policy Practices of Website AdministratorsSena Sahin, Suood Abdulaziz Al-Roomi, Tara Poteat, Frank LiS&P 2023
相关 Paper
- Unveiling the Hunter-Gatherers: Exploring Threat Hunting Practices and Challenges in Cyber DefensePriyanka Badva, Kopo M. Ramokapane, Eleonora Pantano, Awais RashidUSENIX Security 2024 · 被引用 13 次
- Threat Intelligence ComputingXiaokui Shu, Frederico Araujo, Douglas Lee Schales, Marc Ph. Stoecklin 等CCS 2018 · 被引用 71 次
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu 等S&P 2018 · 被引用 151 次
- "Threat modeling is very formal, it's very technical, and also very hard to do correctly": Investigating Threat Modeling Practices in Open-Source Software ProjectsHarjot Kaur, Carson Powers, Ronald E. Thompson III, Sascha Fahl 等USENIX Security 2025
- Benchmarking LLM-Assisted Blue Teaming via Standardized Threat HuntingYuqiao Meng, Luoxi Tang, Feiyang Yu, Xi Li 等ICML 2026 · 被引用 6 次
