首页> 外文会议>IEEE International Conference on Intelligence and Security Informatics >A user-centric machine learning framework for cyber security operations center
【24h】

A user-centric machine learning framework for cyber security operations center

机译:网络安全运营中心的以用户为中心的机器学习框架

获取原文

摘要

To assure cyber security of an enterprise, typically SIEM (Security Information and Event Management) system is in place to normalize security events from different preventive technologies and flag alerts. Analysts in the security operation center (SOC) investigate the alerts to decide if it is truly malicious or not. However, generally the number of alerts is overwhelming with majority of them being false positive and exceeding the SOC's capacity to handle all alerts. Because of this, potential malicious attacks and compromised hosts may be missed. Machine learning is a viable approach to reduce the false positive rate and improve the productivity of SOC analysts. In this paper, we develop a user-centric machine learning framework for the cyber security operation center in real enterprise environment. We discuss the typical data sources in SOC, their work flow, and how to leverage and process these data sets to build an effective machine learning system. The paper is targeted towards two groups of readers. The first group is data scientists or machine learning researchers who do not have cyber security domain knowledge but want to build machine learning systems for security operations center. The second group of audiences are those cyber security practitioners who have deep knowledge and expertise in cyber security, but do not have machine learning experiences and wish to build one by themselves. Throughout the paper, we use the system we built in the Symantec SOC production environment as an example to demonstrate the complete steps from data collection, label creation, feature engineering, machine learning algorithm selection, model performance evaluations, to risk score generation.
机译:为了确保企业的网络安全,通常使用SIEM(安全信息和事件管理)系统来规范来自不同预防技术和标志警报的安全事件。安全运营中心(SOC)的分析师对警报进行调查,以确定警报是否确实是恶意的。但是,通常,警报的数量不胜枚举,其中大多数为误报,并且超出了SOC处理所有警报的能力。因此,可能会错过潜在的恶意攻击和受感染的主机。机器学习是减少误报率和提高SOC分析人员生产率的可行方法。在本文中,我们为实际企业环境中的网络安全运营中心开发了一个以用户为中心的机器学习框架。我们讨论了SOC中的典型数据源,它们的工作流程以及如何利用和处理这些数据集以构建有效的机器学习系统。本文针对的是两组读者。第一组是数据科学家或机器学习研究人员,他们不具备网络安全领域知识,但希望为安全运营中心构建机器学习系统。第二类受众是那些在网络安全方面具有深厚知识和专长,但没有机器学习经验并希望自己构建的网络安全从业人员。在整篇文章中,我们以在Symantec SOC生产环境中构建的系统为例,以演示从数据收集,标签创建,特征工程,机器学习算法选择,模型性能评估到风险评分生成的完整步骤。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号