On the Use of AutoML for Combating Alert Fatigue in Security Operations Centers

被引:0
|
作者
Preuveneers, Davy [1 ]
Llamas, Javier Martinez [1 ]
Bulut, Irfan [2 ]
Rua, Enrique Argones [2 ]
Verfaillie, Pieter [3 ]
Demortier, Vince [3 ]
Surinx, Dimitri [3 ]
Joosen, Wouter [1 ]
机构
[1] Katholieke Univ Leuven, DistriNet, IMEC, Leuven, Belgium
[2] Katholieke Univ Leuven, COSIC, IMEC, Leuven, Belgium
[3] Spotit, Merelbeke, Belgium
关键词
Security Operations Centers; AutoML; Alert fatigue;
D O I
10.1007/978-3-031-54129-2_36
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
An overwhelming number of alerts - especially false ones - can desensitize analysts in security operations centers (SOC), possibly resulting in missed critical incidents and attacks going unnoticed. With inadequate alert monitoring, improper thresholds, and missing feedback loops as lead causes of alert fatigue, we investigate the use of automated machine learning to increase the efficiency of a SOC through automation of false alerts filtering. More specifically, we design a methodology to allow a safer use of AutoML to reduce false alerts, and validate this on a real-world case study. To be more precise, our approach is tailored to address datasets that exhibit limited instances of true positives, possess high dimensionality relative to their size, and demonstrate temporal fluctuations. We have identified diverse setups that provide comparable and reliably effective results in minimizing false positive alerts, all the while avoiding instances of false negatives. Furthermore, we provide valuable insights into the application of these automated frameworks within the realm of security.
引用
收藏
页码:609 / 627
页数:19
相关论文
共 33 条
  • [2] Towards Human-AI Teaming to Mitigate Alert Fatigue in Security Operations Centres
    Chhetri, Mohan baruwal
    Tariq, Shahroz
    Singh, Ronal
    Jalalvand, Fatemeh
    Paris, Cecile
    Nepal, Surya
    ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2024, 24 (03)
  • [3] Security concerns towards Security Operations centers
    Janos, Feher David
    Nguyen Huu Phuoc Dai
    2018 IEEE 12TH INTERNATIONAL SYMPOSIUM ON APPLIED COMPUTATIONAL INTELLIGENCE AND INFORMATICS (SACI), 2018, : 273 - 278
  • [4] Security Operations Centers for Information Security Incident Management
    Miloslayskaya, Natalia
    2016 IEEE 4TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD (FICLOUD 2016), 2016, : 131 - 138
  • [5] Enhancing Collaboration Between Security Analysts in Security Operations Centers
    Cremilleux, Damien
    Bidan, Christophe
    Majorczyk, Fredeic
    Prigent, Nicolas
    RISKS AND SECURITY OF INTERNET AND SYSTEMS, 2019, 11391 : 136 - 142
  • [6] Combating Threat-Alert Fatigue with Online Anomaly Detection Using Isolation Forest
    Aminanto, Muhamad Erza
    Zhu, Lei
    Ban, Tao
    Isawa, Ryoichi
    Takahashi, Takeshi
    Inoue, Daisuke
    NEURAL INFORMATION PROCESSING (ICONIP 2019), PT I, 2019, 11953 : 756 - 765
  • [7] Analysis of SIEM Systems and Their Usage in Security Operations and Security Intelligence Centers
    Miloslavskaya, Natalia
    BIOLOGICALLY INSPIRED COGNITIVE ARCHITECTURES (BICA) FOR YOUNG SCIENTISTS, 2018, 636 : 282 - 288
  • [8] Combat Security Alert Fatigue with AI-Assisted Techniques
    Ban, Tao
    Samuel, Ndichu
    Takahashi, Takeshi
    Inoue, Daisuke
    PROCEEDINGS OF 14TH WORKSHOP ON CYBER SECURITY EXPERIMENTATION AND TEST (CSET 2021), 2021, : 9 - 16
  • [9] Alert Prioritisation in Security Operations Centres: A Systematic Survey on Criteria and Methods
    Jalalvand, Fatemeh
    Baruwal, Mohan
    Nepal, Surya
    Paris, Cecile
    ACM COMPUTING SURVEYS, 2025, 57 (02)
  • [10] Interdisciplinary Optimization of Security Operations Centers with Digital Assistant
    Tureczki, Bence
    Szenes, Katalin
    IEEE 15TH INTERNATIONAL SYMPOSIUM ON APPLIED COMPUTATIONAL INTELLIGENCE AND INFORMATICS (SACI 2021), 2021, : 397 - 401