首页> 外文会议>International Conference on Risks and Security of Internet and Systems >Enhancing Collaboration Between Security Analysts in Security Operations Centers
【24h】

Enhancing Collaboration Between Security Analysts in Security Operations Centers

机译:加强安全运营中心安全分析师之间的协作

获取原文

摘要

Security Operations Centers (SOCs) collect data related to the information systems they protect and process it to detect suspicious activities. In this paper we explain how a SOC is organized, we highlight the current limitations of SOCs and their consequences regarding the performance of the detection service. We propose a new collaboration process to enhance the cooperation between security analysts in order to quickly process security events and define a better workflow that enables them to efficiently exchange feedback. Finally, we design a prototype corresponding to this new model.
机译:安全运营中心(SOC)收集与他们保护的信息系统相关的数据,并处理它以检测可疑活动。在本文中,我们解释了SOC如何组织,我们突出了SOC的当前限制及其关于检测服务性能的后果。我们提出了一种新的协作过程,以提高安全分析师之间的合作,以便快速处理安全事件并定义更好的工作流,使其能够有效地交换反馈。最后,我们设计了对应于此新模型的原型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号