We use cookies, including third-party cookies from Google to serve personalized ads through AdSense, to operate this site and understand how it is used. By continuing to browse, you accept this use. See our Privacy Policy and Terms of Use for details, including how to opt out of personalized advertising.
Accept
SmartData CollectiveSmartData Collective
  • Analytics
    AnalyticsShow More
    chatgpt image jul 21, 2026, 04 34 30 pm
    4 Core Benefits of Predictive Maintenance after Vibration Analysis
    10 Min Read
    How Does Data Mining Boost Customer Satisfaction in Logistics? Harnessing Analytics for Results -- AI-generated illustration
    How Does Data Mining Boost Customer Satisfaction in Logistics? Harnessing Analytics for Results
    11 Min Read
    chatgpt image jul 13, 2026, 04 23 45 pm
    How Data Analytics Helps Companies Improve User Engagement
    19 Min Read
    chatgpt image jul 13, 2026, 03 59 46 pm
    How Data Analytics Improves Multi-Location Search Strategies
    10 Min Read
    cybersecurity efforts
    How Behavioral Analytics and AI Are Redefining Cybersecurity for Boca Raton Businesses
    14 Min Read
  • Big Data
  • BI
  • Exclusive
  • IT
  • Marketing
  • Software
Search
© 2008-25 SmartData Collective. All Rights Reserved.
Reading: Enhancing Collective Defense with Taxonomies for Operational Cyber Defense
Share
Notification
Font ResizerAa
SmartData CollectiveSmartData Collective
Font ResizerAa
Search
  • About
  • Help
  • Privacy
Follow US
© 2008-23 SmartData Collective. All Rights Reserved.
SmartData Collective > Data Management > Best Practices > Enhancing Collective Defense with Taxonomies for Operational Cyber Defense
Best PracticesBook ReviewBusiness IntelligenceData MiningPrivacySecurity

Enhancing Collective Defense with Taxonomies for Operational Cyber Defense

BobGourley
BobGourley
6 Min Read
Enhancing Collective Defense with Taxonomies for Operational Cyber Defense
Photo by whitesession on Pixabay (https://pixabay.com/photos/doctor-op-medicine-operation-2722943/)
SHARE

Cyberspace is our interconnected information technology. And since everything either is or is becoming connected, one of the defining characteristics of cyberspace is its complexity. This adds burden to cyber defenders. Defense teams require experience, education, training and a mindset that lets them continually learn. They also must forge broad teams across multiple subject and functional areas. An ability to rapidly collaborate and exchange data while in a fight is a must.

More Read

Could Beethoven Implement Analytics-based Performance Management?
Could Beethoven Implement Analytics-based Performance Management?
Here’s How to Use Decision Management to Improve Cross-Channel Experience
Mobile Security: How Safe is Your Data?
Sizing Up Data For CRM: Big Doesn’t Mean Valuable Data
Marketing Optimization with LityxIQ

For years computer security professionals have sought the best ways to dialog on incidents, and some great foundational work has been done in this area. This post reviews two key works I have found to be of special relevance to today’s cyber defenders. One is a 1998 publication titled “A Common Language for Computer Security Incidents,” the other is a matrix developed by Dr. John Mallary of MIT’s CSAIL. Both these documents have already had impacts on the community and the many automated data exchange models in place today. But both are also relevant to the human to human dialog and understanding on cyberspace operations and are important pieces for continued study.

What is a taxonomy?

A taxonomy is a set of related terms. It is a classification scheme. How do you judge a good taxonomy? It should meet several criteria, including being:

  1. Mutually exclusive – classifying in one category excludes all others because categories do not overlap,
  2. Exhaustive – taken together, the categories include all possibilities,
  3. Unambiguous – clear and precise so that classification is not uncertain, regardless of who is classifying,
  4. Repeatable – repeated applications result in the same classification, regardless of who is classifying,
  5. Accepted – logical and intuitive so that categories could become generally approved,
  6. Useful – could be used to gain insight into the field of inquiry

Caution: there is probably no such thing as a perfect taxonomy. They are all approximations of reality and therefore you will never have one that meets every criteria perfectly. But the characteristics above are good goals to judge the taxonomy by.

When it comes to cyberspace activity, the taxonomy presented by John Howard and Thomas Longstaff comes pretty close to meeting those goals which is why it is still so relevant today.

They define a taxonomy of terms in a way that can be logically and graphically expressed.

See, for example, the picture below.

This is from their report and it lets you related terms in a way that can help in dialog between humans and also help in automating information exchange.

The top line of words can be easily thought of as a sentence. Attackers use Tools against Vulnerabilities to cause an Action against a Target to achieve an Unauthorized Result to meet an Objective.

The details of their work spell out with clarify what the individual terms are and that is also a huge help to dialog. Over time there has been a little modification by operational users on some of the terms, and the adversaries in cyberspace have continued to change their craft and a few more terms have entered the lexicon. But overall the framework is sound.

For organizations who need to focus more on the threat, taxonomies have also been devised that delve deeper into the motivations and resources and capabilities of adversaries. Most computer security books today have some articulation of the threat at a high level, but to find the most operationally useful articulation of the threat I recommend the works of John Mallery of MIT’s Computer Science and Artificial Intelligence Laboratory. With John’s permission I have reproduced one of his taxonomy’s of the threat below:

[click image to open full size]

Note that John’s articulation of threat actors is different than the October 1998 work of Sandia and CERT. Part of that is due to the passing of time, but you should also keep in mind that although we like a common language for all mission areas, there are also differences of taxonomies based on how information is used. Some organizations may choose to slightly modify John’s approach (but I would recommend the default be to keep his taxonomy unless there is specific reason to clarify, since it is helpful to have a common expression of terms).

John is working on a paper that captures many of the key considerations from his work in things cyber. As soon as that is publicly available we will review it here.

Share This Article
Facebook Pinterest LinkedIn
Share

Follow us on Facebook

Latest News

How Great Content Moves Through A Marketing Ecosystem -- AI-generated illustration
How Great Content Moves Through A Marketing Ecosystem
Exclusive Infographic Marketing
What Your Brand Misses That Data Reveals -- AI-generated illustration
What Your Brand Misses That Data Reveals
Big Data Exclusive Infographic
5 Common Mistakes Businesses Make During the Risk Assessment Process -- AI-generated illustration
5 Common Mistakes Businesses Make During the Risk Assessment Process
Business Intelligence Exclusive Risk Management
Protecting Brand Reputation During Digital Expansion -- AI-generated illustration
Protecting Brand Reputation During Digital Expansion
Business Rules Infographic

Stay Connected

1.2KFollowersLike
33.7KFollowersFollow
222FollowersPin

You Might also Like

Smarter Planet Means the Deep Web
The Deep Web (or Deepnet,...
Business IntelligenceData MiningData WarehousingPredictive Analytics

Smarter Planet Means the Deep Web The Deep Web (or Deepnet,…

1 Min Read
The Nature of Big Data and the Skills of Data Scientists
AnalyticsBig DataData MiningJobs

The Nature of Big Data and the Skills of Data Scientists

7 Min Read
"Good Enough" Data Analysis Will Lead to Good Data Analysis
AnalyticsBest PracticesCulture/Leadership

“Good Enough” Data Analysis Will Lead to Good Data Analysis

3 Min Read
Using R in Astronomy
Data MiningPredictive Analytics

Using R in Astronomy

1 Min Read

SmartData Collective is one of the largest & trusted community covering technical content about Big Data, BI, Cloud, Analytics, Artificial Intelligence, IoT & more.

AI and chatbots
Chatbots and SEO: How Can Chatbots Improve Your SEO Ranking?
Artificial Intelligence Chatbots Exclusive
ai chatbot
How AI Website Chatbots Improve Customer Support and Lead Generation
Chatbots Exclusive

Quick Link

  • About
  • Contact
  • Privacy
Follow US
© 2008-26 SmartData Collective. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?