首页> 外文期刊>IEEE systems journal >Optimal Assignment of Sensors to Analysts in a Cybersecurity Operations Center
【24h】

Optimal Assignment of Sensors to Analysts in a Cybersecurity Operations Center

机译:在网络安全运营中心中,将传感器最佳地分配给分析人员

获取原文
获取原文并翻译 | 示例
           

摘要

A cybersecurity operations center (CSOC) analyzes a large volume of alerts generated by intrusion detection systems, which process data froma number of sensors. Sensors are assigned to analysts, and the number of sensors is much larger than the number of analysts at the CSOC. Hence, sensors are grouped into clusters, which are allocated to analysts for investigation. There are two essential properties that must be met in the above grouping and allocation process: 1) meeting the cluster's requirement for specific analyst expertise mix, complete tool coverage that allows the analysts to handle the type of alerts generated, and analyst credentials such as security clearances; and 2) minimizing and balancing the number of unanalyzed alerts among clusters at the end of the daily work shift because an imbalance or a large number of unanalyzed alerts among clusters due to factors such as lack of analyst credentials or tooling expertise in a cluster would pose a security risk to the organization. Current practice at CSOCs is to group and then to allocate, which may not meet the above properties because grouping and allocation steps are done independently that remain static for a long time despite uncertainties such as day-to-day changes in alert generation rates and analyst absenteeism. This paper meets both properties by presenting an optimization model, in which grouping of sensors to clusters and analyst allocation to clusters is achieved simultaneously. The integrated methodology produces optimal sensor grouping and analyst allocation that is adaptable to changing shift conditions.
机译:网络安全运营中心(CSOC)分析由入侵检测系统生成的大量警报,这些警报处理来自多个传感器的数据。传感器分配给分析人员,传感器的数量比CSOC的分析人员的数量大得多。因此,传感器被分为几类,分配给分析人员进行调查。在上述分组和分配过程中,必须满足两个基本属性:1)满足集群对特定分析师专业知识组合的要求,完整的工具范围(允许分析师处理所生成警报的类型)以及分析师凭据(例如安全性)间隙;和2)在日常工作结束时,最小化和平衡集群中未分析警报的数量,这是由于集群中缺乏分析员凭证或工具专业知识等因素造成的不平衡或大量未分析警报的存在对组织的安全风险。 CSOC的当前做法是先分组然后再分配,这可能无法满足上述属性,因为分组和分配步骤是独立完成的,尽管存在不确定性,例如警报生成率和分析人员的日常变化,但长期保持静态旷工。本文通过提出一个优化模型来满足这两个属性,在该模型中,可以同时实现传感器到集群的分组和分析师到集群的分配。集成的方法可生成最佳的传感器分组和分析人员分配,以适应变化的换档条件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号