On the Use of AutoML for Combating Alert Fatigue in Security Operations Centers

被引:0
|
作者
Preuveneers, Davy [1 ]
Llamas, Javier Martinez [1 ]
Bulut, Irfan [2 ]
Rua, Enrique Argones [2 ]
Verfaillie, Pieter [3 ]
Demortier, Vince [3 ]
Surinx, Dimitri [3 ]
Joosen, Wouter [1 ]
机构
[1] Katholieke Univ Leuven, DistriNet, IMEC, Leuven, Belgium
[2] Katholieke Univ Leuven, COSIC, IMEC, Leuven, Belgium
[3] Spotit, Merelbeke, Belgium
关键词
Security Operations Centers; AutoML; Alert fatigue;
D O I
10.1007/978-3-031-54129-2_36
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
An overwhelming number of alerts - especially false ones - can desensitize analysts in security operations centers (SOC), possibly resulting in missed critical incidents and attacks going unnoticed. With inadequate alert monitoring, improper thresholds, and missing feedback loops as lead causes of alert fatigue, we investigate the use of automated machine learning to increase the efficiency of a SOC through automation of false alerts filtering. More specifically, we design a methodology to allow a safer use of AutoML to reduce false alerts, and validate this on a real-world case study. To be more precise, our approach is tailored to address datasets that exhibit limited instances of true positives, possess high dimensionality relative to their size, and demonstrate temporal fluctuations. We have identified diverse setups that provide comparable and reliably effective results in minimizing false positive alerts, all the while avoiding instances of false negatives. Furthermore, we provide valuable insights into the application of these automated frameworks within the realm of security.
引用
收藏
页码:609 / 627
页数:19
相关论文
共 33 条
  • [22] Freight operations in city centers: A land use conflict in urban planning
    Cruz-Daravina, Paola Andrea
    Suescun, Juan Pablo Bocarejo
    LAND USE POLICY, 2021, 108
  • [23] MEDICATION ALERT FATIGUE: THE DESIGN AND USE OF A MEDICATION ALERT DASHBOARD AS PART OF A COMPREHENSIVE APPROACH TO DRUG-DRUG INTERACTION ALERTS
    Ahumada, Luis M.
    Desai, Bimal
    Simpao, Allan F.
    Rehman, Mohamed A.
    Shelov, Eric D.
    ANESTHESIA AND ANALGESIA, 2013, 117 : 62 - 63
  • [24] A Survey on TLS-Encrypted Malware Network Traffic Analysis Applicable to Security Operations Centers
    Oh, Chaeyeon
    Ha, Joonseo
    Roh, Heejun
    APPLIED SCIENCES-BASEL, 2022, 12 (01):
  • [25] Fatigue and Stimulant Use in Military Fighter Aircrew During Combat Operations
    Gore, Russell K.
    Webb, Timothy S.
    Hermes, Eric D. A.
    AVIATION SPACE AND ENVIRONMENTAL MEDICINE, 2010, 81 (08): : 719 - 727
  • [26] Problems of the Use of Private Military and Security Companies in the US military operations
    Novikova, D. O.
    MGIMO REVIEW OF INTERNATIONAL RELATIONS, 2010, (03): : 89 - 96
  • [27] Using the Activity Theory to Identify the Challenges of Designing Elearning Tools based on Machine Learning for Security Operations Centers
    Cazacu, Mihail
    Bodea, Constanta
    Dascalu, Maria-Iuliana
    Cucu, Cristian
    NEW TECHNOLOGIES AND REDESIGNING LEARNING SPACES, VOL I, 2019, : 452 - 461
  • [28] The 2nd international workshop on next generation security operations centers (NG-SOC 2020)
    Chiscop, Irina
    Jirsik, Tomas
    Mandal, Avikarsha
    Piatkowska, Ewa
    ACM International Conference Proceeding Series, 2020,
  • [29] APROTININ THERAPY IN CARDIAC OPERATIONS - A REPORT ON USE IN 41 CARDIAC CENTERS IN THE UNITED-KINGDOM
    BIDSTRUP, BP
    HARRISON, J
    ROYSTON, D
    TAYLOR, KM
    TREASURE, T
    ANNALS OF THORACIC SURGERY, 1993, 55 (04): : 971 - 976
  • [30] The Legality of the Use of Private Military and Security Companies in UN Peacekeeping and Peace Enforcement Operations
    Janaby, Mohamad Ghazi
    JOURNAL OF INTERNATIONAL HUMANITARIAN LEGAL STUDIES, 2015, 6 (01) : 147 - 187