首页> 外文期刊>ACM transactions on the web >An Outsourcing Model for Alert Analysis in a Cybersecurity Operations Center
【24h】

An Outsourcing Model for Alert Analysis in a Cybersecurity Operations Center

机译:网络安全运营中心警报分析的外包模型

获取原文
获取原文并翻译 | 示例

摘要

A typical Cybersecurity Operations Center (CSOC) is a service organization. It hires and trains analysts, whose task is to perform analysis of alerts that were generated while monitoring the client's networks. Due to ever-increasing financial and infrastructure burden on a CSOC driven by the rapidly growing demand for security services, it would become prohibitively expensive to continually expand the size of a CSOC to meet the demands in the future. An alternative solution is to outsource the alert analysis process to on-demand analysts, to provide scalable CSOC service to its clients with features, such as (1) higher throughput, (2) higher quality, and (3) more economical service than the current in-house service. The current outsourcing model is not cost effective and an exact optimization model is computationally inefficient. This article presents a novel two-step sequential mixed integer programming optimization method that is used in the development of a new decision-support business model for outsourcing the alert analysis process. It is demonstrated that through this model, a CSOC can effectively deliver its alert management services with the above-mentioned features. Results indicate that the model is scalable, computationally viable, real-time implementable, and can deliver CSOC services that meet the service-level agreement (SLA) between the CSOC and its client. In addition, the article provides valuable insights into the cost of operating the new business process outsourcing model for cybersecurity services.
机译:典型的网络安全运营中心(CSOC)是服务组织。它雇用并培训分析师,其任务是对监视客户网络的同时生成的警报进行分析。由于越来越多的金融和基础设施负担在CSOC驱动的安全服务的需求迅速,这将使不断扩大CSOC的规模,以满足未来的需求,这将变得非常昂贵。另一种解决方案是将警报分析过程外包给按需分析师,为其客户提供可扩展的CSOC服务,例如(1)更高的吞吐量,(2)质量更高,(3)比该产品更高的服务目前的内部服务。当前的外包模型不具有成本效益,并且精确的优化模型是计算效率低下的。本文介绍了一种新颖的两步顺序混合整数编程优化方法,用于开发用于外包警报分析过程的新决策支持业务模型。据证明,通过该模型,CSOC可以通过上述特征有效地提供其警报管理服务。结果表明,该模型是可扩展的,计算可行,实时可实现的,并且可以提供CSOC与其客户端之间的服务级协议(SLA)的CSOC服务。此外,本文还提供了有价值的见解,以运营网络安全服务新业务流程外包模型的成本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号