Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

An Assessment of the Usability of Machine Learning Based Tools for the Security Operations Center

Conference ·
Gartner, a large research and advisory company, anticipates that by 2024 80% of security operation centers (SOCs) will use machine learning (ML) based solutions to enhance their operations. 1 1 https://www.ciodive.com/news/how-data-science-tools-can-lighten-the-load-for-cybersecurity-teams/572209/ In light of such widespread adoption, it is vital for the research community to identify and address usability concerns. This work presents the results of the first in situ usability assessment of ML-based tools. With the support of the US Navy, we leveraged the national cyber range-a large, air-gapped cyber testbed equipped with state-of-the-art network and user emulation capabilities-to study six US Naval SOC analysts' usage of two tools. Our analysis identified several serious usability issues, including multiple violations of established usability heuristics for user interface design. We also discovered that analysts lacked a clear mental model of how these tools generate scores, resulting in mistrust a and/or misuse of the tools themselves. Surprisingly, we found no correlation between analysts' level of education or years of experience and their performance with either tool, suggesting that other factors such as prior background knowledge or personality play a significant role in ML-based tool usage. Our findings demonstrate that ML-based security tool vendors must put a renewed focus on working with analysts, both experienced and inexperienced, to ensure that their systems are usable and useful in real-world security operations settings.
Research Organization:
Oak Ridge National Laboratory (ORNL), Oak Ridge, TN (United States)
Sponsoring Organization:
USDOE
DOE Contract Number:
AC05-00OR22725
OSTI ID:
1766395
Country of Publication:
United States
Language:
English

Similar Records

Bayesian Attack Model (BAM) User Story
Technical Report · Mon Sep 01 00:00:00 EDT 2025 · OSTI ID:2589620

Cyber threat assessment of machine learning driven autonomous control systems of nuclear power plants
Journal Article · Thu Nov 09 19:00:00 EST 2023 · Progress in Nuclear Energy · OSTI ID:2279000

Real-World Cyber Security Demonstration for Networked Electric Drives
Journal Article · Tue Mar 11 20:00:00 EDT 2025 · IEEE Journal of Emerging and Selected Topics in Power Electronics · OSTI ID:3011825

Related Subjects