下一代安全运营中心(SOC): 自动化警报过载[2021]23页 “英文电子版”

ID:27836

阅读量:0

大小:0.39 MB

页数:23页

时间:2023-01-01

金币:20

上传者:战必胜
© 2021 The SANS Institute, Author Retains Full Rights

21
 
Next Gen SOC: Automating Alert Overload
GIAC (GCDA) Gold Certification
Author: Jon-Michael Lacek, jmlacek@gmail.com
Advisor: Russell Eubanks
Accepted: July 6, 2021
Abstract
In every Security Operations Center (SOC) analysts continue to be flooded with alerts.
As the adversary continues to develop and enhance their attack methodologies, security
vendors continue to produce new and innovative ways of detecting alerts. These
technologies/solutions leverage machine learning algorithms to build a baseline profile on
user behavior and network traffic to alert when activity falls outside that established
pattern. Unfortunately, the alerts generated from the machine learning solutions add to an
already overwhelmed SOC. In addition to the growth in toolset usage, the amount of data
coming in from those tools continue to grow, all while the headcount within a SOC
typically does not. While traditional SOCs focus on tuning alerts to meet their
organizational behaviors, this research focuses on combining detection mechanisms from
various tools or cross-referencing data from the different sources in an automated
fashion. By modifying the fidelity of these alerts, analysts are left with more context and
actionable alerts to investigate.
资源描述:

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭