{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T02:53:33Z","timestamp":1782442413200,"version":"3.54.5"},"reference-count":35,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2019,10,22]],"date-time":"2019-10-22T00:00:00Z","timestamp":1571702400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2019,10,22]],"date-time":"2019-10-22T00:00:00Z","timestamp":1571702400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"published-print":{"date-parts":[[2019,12]]},"abstract":"<jats:title>Abstract<\/jats:title>\n<jats:p>Humans are commonly seen as the weakest link in corporate information security. This led to a lot of effort being put into security training and awareness campaigns, which resulted in employees being less likely the target of successful attacks. Existing approaches, however, do not tap the full potential that can be gained through these campaigns. On the one hand, human perception offers an additional source of contextual information for detected incidents, on the other hand it serves as information source for incidents that may not be detectable by automated procedures. These approaches only allow a text-based reporting of basic incident information. A structured recording of human delivered information that also provides compatibility with existing SIEM systems is still missing. In this work, we propose an approach, which allows humans to systematically report perceived anomalies or incidents in a structured way. Our approach furthermore supports the integration of such reports into analytics systems. Thereby, we identify connecting points to SIEM systems, develop a taxonomy for structuring elements reportable by humans acting as a security sensor and develop a structured data format to record data delivered by humans. A prototypical human-as-a-security-sensor wizard applied to a real-world use-case shows our proof of concept.<\/jats:p>","DOI":"10.1186\/s42400-019-0040-0","type":"journal-article","created":{"date-parts":[[2019,10,23]],"date-time":"2019-10-23T04:29:57Z","timestamp":1571804997000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":22,"title":["Human-as-a-security-sensor for harvesting threat intelligence"],"prefix":"10.1186","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1119-4715","authenticated-orcid":false,"given":"Manfred","family":"Vielberth","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Florian","family":"Menges","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"G\u00fcnther","family":"Pernul","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2019,10,22]]},"reference":[{"key":"40_CR1","unstructured":"Anti-Phishing Working Group, IReport Phishing. \nhttps:\/\/www.antiphishing.org\/report-phishing\/overview\/\n\n. Accessed 19.01.2019."},{"key":"40_CR2","doi-asserted-by":"crossref","unstructured":"Appala, S, Cam-Winget N, McGrew D, Verma J (2015) An Actionable Threat Intelligence system using a Publish-Subscribe communications model. Proc 2nd ACM Workshop Inf Sharing Collab Secur - WISCS \u201915:61\u201370.","DOI":"10.1145\/2808128.2808131"},{"key":"40_CR3","unstructured":"Barnum, S (2014) Standardizing cyber threat intelligence information with the Structured Threat Information eXpression (STIX). \nhttp:\/\/stixproject.github.io\/getting-started\/whitepaper\/\n\n. Accessed 2019-02-21."},{"issue":"5","key":"40_CR4","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1109\/MSP.2014.103","volume":"12","author":"S Bhatt","year":"2014","unstructured":"Bhatt, S, Manadhata PK, Zomlot L (2014) The operational role of security information and event management systems. IEEE Secur Privacy 12(5):35\u201341.","journal-title":"IEEE Secur Privacy"},{"key":"40_CR5","doi-asserted-by":"crossref","unstructured":"B\u00f6hm, F, Menges F, Pernul G (2018) Graph-based visual analytics for cyber threat intelligence. Cybersecurity 1(1).","DOI":"10.1186\/s42400-018-0017-4"},{"key":"40_CR6","doi-asserted-by":"crossref","unstructured":"Burger, EW, Goodman MD, Kampanakis P, Zhu KA (2014) Taxonomy model for cyber threat intelligence information exchange technologies In: WISCS \u201914 Proceedings of the 2014 ACM Workshop on Information Sharing & Collaborative Security, 51\u201360.","DOI":"10.1145\/2663876.2663883"},{"key":"40_CR7","unstructured":"Crowley, C, Pescatore J (2018) Sans 2018 security operations center survey."},{"key":"40_CR8","unstructured":"Dandurand, L, Kaplan A, K\u00e1cha P, Kadobayashi Y, Kompanek A, Lima T, Millar T, Nazario J, Perlotto R, Young W (2015) Standards and Tools for Exchange and Processing of Actionable Information."},{"issue":"5","key":"40_CR9","doi-asserted-by":"publisher","first-page":"410","DOI":"10.1108\/IMCS-07-2013-0053","volume":"22","author":"S Fenz","year":"2014","unstructured":"Fenz, S, Heurix J, Neubauer T, Pechstein F (2014) Current challenges in information security risk management. Inf Manag & Comput Secur 22(5):410\u2013430.","journal-title":"Inf Manag & Comput Secur"},{"key":"40_CR10","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1007\/s00502-015-0289-2","volume":"18","author":"F Fransen","year":"2015","unstructured":"Fransen, F, Smulders A, Kerkdijk R (2015) Cyber security information exchange to gain insight into the effects of cyber threats and incidents. Elektrotechnik & Informationstechnik 18:106\u2013112.","journal-title":"Elektrotechnik & Informationstechnik"},{"key":"40_CR11","unstructured":"Google LLC. Gmail. \nhttps:\/\/mail.google.com\/\n\n. Accessed 19.01.2019."},{"key":"40_CR12","doi-asserted-by":"publisher","first-page":"6910","DOI":"10.1109\/ACCESS.2016.2616285","volume":"4","author":"R Heartfield","year":"2016","unstructured":"Heartfield, R, Loukas G, Gan D (2016) You are probably not the weakest link: Towards practical prediction of susceptibility to semantic social engineering attacks. IEEE Access 4:6910\u20136928.","journal-title":"IEEE Access"},{"key":"40_CR13","doi-asserted-by":"publisher","first-page":"101","DOI":"10.1016\/j.cose.2018.02.020","volume":"76","author":"R Heartfield","year":"2018","unstructured":"Heartfield, R, Loukas G (2018) Detecting semantic social engineering attacks with the weakest link: Implementation and empirical evaluation of a human-as-a-security-sensor framework. Comput Secur 76:101\u2013127.","journal-title":"Comput Secur"},{"key":"40_CR14","volume-title":"Foundations of Information Security: Based on ISO 27001 and ISO 27002","author":"J Hintzbergen","year":"2015","unstructured":"Hintzbergen, J, Hintzbergen K, Smulders A, Baars H (2015) Foundations of Information Security: Based on ISO 27001 and ISO 27002. 3rd. Van Haren Publishing, Zaltbommel."},{"key":"40_CR15","doi-asserted-by":"crossref","unstructured":"Holik, F, Horalek J, Neradova S, Zitta S, Marik O (2015) The deployment of security information and event management in cloud infrastructure In: 2015 25th International Conference Radioelektronika (RADIOELEKTRONIKA), 399\u2013404.","DOI":"10.1109\/RADIOELEK.2015.7128982"},{"key":"40_CR16","unstructured":"ISO\/IEC 27001: Information technology \u2013 Security techniques \u2013 Information security management systems \u2013 Requirements (2013) Technical report. Int Org Standard."},{"key":"40_CR17","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-30r1","volume-title":"Guide for Conducting Risk Assessments","author":"Joint Task Force Transformation Initiative","year":"2012","unstructured":"Joint Task Force Transformation Initiative (2012) Guide for Conducting Risk Assessments. National Institute of Standards and Technology, Gaithersburg, MD."},{"issue":"1","key":"40_CR18","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1109\/MCC.2015.2","volume":"2","author":"NV Juliadotter","year":"2015","unstructured":"Juliadotter, NV, Choo K-KR (2015) Cloud attack and risk assessment taxonomy. IEEE Cloud Comput 2(1):14\u201320.","journal-title":"IEEE Cloud Comput"},{"issue":"1","key":"40_CR19","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1007\/BF03345922","volume":"7","author":"Stephan Klingner","year":"2012","unstructured":"Klingner, S, Becker M (2012) Formal modelling of components and dependencies for configuring product-service-systems. Enterp Model Inf Syst Architectures 7(1).","journal-title":"Enterprise Modelling and Information Systems Architectures"},{"key":"40_CR20","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1007\/978-3-319-25658-0_4","volume-title":"Participatory Sensing, Opinions and Collective Awareness","author":"V Kostakos","year":"2017","unstructured":"Kostakos, V, Rogstadius J, Ferreira D, Hosio S, Goncalves J (2017) Human sensors In: Participatory Sensing, Opinions and Collective Awareness, 69\u201392.. Springer, Cham."},{"issue":"5","key":"40_CR21","first-page":"44","volume":"204","author":"S Lineberry","year":"2007","unstructured":"Lineberry, S (2007) The human element: The weakest link in information security. J Account 204(5):44.","journal-title":"J Account"},{"key":"40_CR22","unstructured":"Marinos, L (2016) ENISA Threat Taxonomy: A Tool for Structuring Threat Information."},{"key":"40_CR23","unstructured":"Mello, J (2017) Security Awareness Training Explosion. \nhttps:\/\/cybersecurityventures.com\/security-awareness-training-report\/\n\n. Accessed 28.02.2019."},{"key":"40_CR24","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1016\/j.cose.2017.10.009","volume":"73","author":"F Menges","year":"2018","unstructured":"Menges, F, Pernul G (2018) A comparative analysis of incident reporting formats. Comput Secur 73:87\u2013101.","journal-title":"Comput Secur"},{"key":"40_CR25","unstructured":"Microsoft CorporationDeal with abuse, phishing, or spoofing in Outlook.com. \nhttps:\/\/support.office.com\/en-us\/article\/deal-with-abuse-phishing-or-spoofing-in-outlook-com-0d882ea5-eedc-4bed-aebc-079ffa1105a3\n\n."},{"issue":"3","key":"40_CR26","doi-asserted-by":"publisher","first-page":"336","DOI":"10.1057\/ejis.2012.26","volume":"22","author":"RC Nickerson","year":"2013","unstructured":"Nickerson, RC, Varshney U, Muntermann J (2013) A method for taxonomy development and its application in information systems. Eur J Inf Syst 22(3):336\u2013359.","journal-title":"Eur J Inf Syst"},{"issue":"3","key":"40_CR27","doi-asserted-by":"publisher","first-page":"45","DOI":"10.2753\/MIS0742-1222240302","volume":"24","author":"K Peffers","year":"2007","unstructured":"Peffers, K, Tuunanen T, Rothenberger MA, Chatterjee S (2007) A design science research methodology for information systems research. J Manag Inf Syst 24(3):45\u201377.","journal-title":"J Manag Inf Syst"},{"key":"40_CR28","doi-asserted-by":"crossref","unstructured":"Rahman, SS, Heartfield R, Oliff W, Loukas G, Filippoupolitis A (2017) Assessing the cyber-trustworthiness of human-as-a-sensor reports from mobile devices In: 2017 IEEE 15th International Conference on Software Engineering Research, Management and Applications (SERA), 387\u2013394.","DOI":"10.1109\/SERA.2017.7965756"},{"key":"40_CR29","unstructured":"Shackleford, D, SANS Institute (2015) Who\u2019s Using Cyberthreat Intelligence and How?\nhttps:\/\/www.alienvault.com\/docs\/SANS-Cyber-Threat-Intelligence-Survey-2015.pdf\n\n. Accessed 2019-02-21."},{"key":"40_CR30","unstructured":"Sauerwein, C, Sillaber CN, Mussmann A, Breu R (2017) Threat intelligence sharing platforms: An exploratory study of software vendors and research perspectives In: 13. Internationale Tagung Wirtschaftsinformatik, WI 2017, St. Gallen."},{"key":"40_CR31","unstructured":"Golovanov, S (2018) DarkVishnya: Banks attacked through direct connection to local network. \nhttps:\/\/securelist.com\/darkvishnya\/89169\/\n\n."},{"key":"40_CR32","unstructured":"Turnbull, J (2019) The Art of Monitoring. Version 1.0.4."},{"key":"40_CR33","doi-asserted-by":"crossref","unstructured":"Venable, J, Pries-Heje J, Baskerville R (2012) A comprehensive framework for evaluation in design science research In: International Conference on Design Science Research in Information Systems, 423\u2013438.","DOI":"10.1007\/978-3-642-29863-9_31"},{"key":"40_CR34","unstructured":"Vielberth, M, Pernul G (2018) A security information and event management pattern In: 12th Latin American Conference on Pattern Languages of Programs (SugarLoafPLoP 2018)."},{"key":"40_CR35","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1109\/IPSN.2014.6846739","volume-title":"IPSN-14 Proceedings of the 13th International Symposium on Information Processing in Sensor Networks","author":"D Wang","year":"2014","unstructured":"Wang, D, Amin MT, Li S, Abdelzaher T, Kaplan L, Gu S, Pan C, Liu H, Aggarwal CC, Ganti R, Wang X, Mohapatra P, Szymanski B, Le H (2014) Using humans as sensors: An estimation-theoretic perspective In: IPSN-14 Proceedings of the 13th International Symposium on Information Processing in Sensor Networks, 35\u201346.. IEEE, Piscataway."}],"updated-by":[{"DOI":"10.1186\/s42400-019-0041-z","type":"correction","label":"Correction","source":"publisher","updated":{"date-parts":[[2019,11,26]],"date-time":"2019-11-26T00:00:00Z","timestamp":1574726400000}}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-019-0040-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1186\/s42400-019-0040-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-019-0040-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,10,20]],"date-time":"2020-10-20T23:07:55Z","timestamp":1603235275000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-019-0040-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,10,22]]},"references-count":35,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2019,12]]}},"alternative-id":["40"],"URL":"https:\/\/doi.org\/10.1186\/s42400-019-0040-0","relation":{"correction":[{"id-type":"doi","id":"10.1186\/s42400-019-0041-z","asserted-by":"object"}]},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,10,22]]},"assertion":[{"value":"24 April 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 August 2019","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 October 2019","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 November 2019","order":4,"name":"change_date","label":"Change Date","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Correction","order":5,"name":"change_type","label":"Change Type","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"In the original publication of this article (Vielberth et al. 2019), the author list was not completed.","order":6,"name":"change_details","label":"Change Details","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"23"}}