首页> 外文期刊>IEEE transactions on information forensics and security >A Two-Step Approach to Optimal Selection of Alerts for Investigation in a CSOC
【24h】

A Two-Step Approach to Optimal Selection of Alerts for Investigation in a CSOC

机译:CSOC中调查警报的最佳选择的两步法

获取原文
获取原文并翻译 | 示例
           

摘要

A Cyber Security Operations Center (CSOC) is responsible for investigating all the alerts generated from the intrusion detection systems to identify suspicious activities in a timely manner. There exists a critical gap between the time needed (demand) and the time available (limited analyst resource) for alert investigation at a CSOC. Hence, alert prioritization is important, for which CSOCs employ ad-hoc filtering methods to prune and triage the alerts that are presented to the analysts for investigation. One of the major drawbacks of the ad-hoc methods is that they do not comprehensively take into consideration the organization-specific factors such as mission and asset criticality, CSOC resource availability, demand variations, and the desired CSOC performance metrics. Hence, an ad-hoc triaging (or prioritization) method is insufficient, and an intelligent method for optimal selection of alerts that considers the above-mentioned organization-specific factors must be developed, which is described as a two-step process in this paper. First, a composite risk score of each alert is determined using a quantitative value function hierarchy process, which takes into account several organization-specific factors. Second, an optimization model selects a list of alerts for investigation that optimizes the CSOC performance metrics for a given demand subject to its resource constraints. Experimental results show that the alerts that pertain to mission criticalities are handled in a timelier manner as compared to current practices at the CSOCs. The average persistence time of an alert in the CSOC system is also shown to significantly reduce with this new approach, which is a paradigm shift in providing a stronger cyber-defense system by protecting the critical constituents of an organization.
机译:网络安全运营中心(CSOC)负责调查从入侵检测系统生成的所有警报,以及时识别可疑活动。在CSOC进行警报调查所需的时间(需求)与可用时间(有限的分析人员资源)之间存在关键的差距。因此,警报优先级很重要,为此,CSOC使用临时过滤方法来修剪和分类呈现给分析人员进行调查的警报。临时方法的主要缺点之一是它们没有全面考虑组织特定的因素,例如任务和资产的关键性,CSOC资源的可用性,需求变化以及所需的CSOC绩效指标。因此,临时分类(或优先级)方法是不够的,必须开发一种考虑上述组织特定因素的最优警报选择的智能方法,本文将其描述为两步过程。首先,使用定量值函数层次结构过程确定每个警报的综合风险评分,该过程考虑了几个组织特定的因素。其次,优化模型选择要调查的警报列表,以根据给定需求的资源约束来优化CSOC性能指标。实验结果表明,与CSOC的当前实践相比,与任务关键性有关的警报得到了及时处理。通过这种新方法,CSOC系统中警报的平均持续时间也显着减少,这是通过保护组织的关键组成部分提供更强大的网络防御系统的范式转变。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号