IntelliSOAR: Intelligent Alert Enrichment Using Security Orchestration Automation and Response (SOAR)


연구 분야: Safety



학회: International Conference on Information Systems Security


초록

A typical Security Operations Center (SOC) receives several millions of alerts everyday. An analyst in SOC needs to use sophisticated tools to drill down to the most concerning alerts. Security Orchestration Automation and Response (SOAR) provide the much needed relief to them. However, though a large number of SOAR tools are available, customising them to the specific requirements is a grand challenge. This study bridges the gap between the theoretical understanding of SOAR system and practical implementation by step wise elaborating the SOAR architecture with the help of a use case of Intelligent alert enrichment using SOAR system. The process of data ingestion, and integration with various tools, workflow and orchestration are described in detail. An use case illustrating the automation of alert enrichment is presented. Various open source tools and technologies required for SOAR system implementation are explained. Also a summary of other popular SOAR tools are provided.


Author Profile
Surabhi Dwivedi

Centre for Development of Advanced Computing (C-DAC) Bengaluru 560100 India

India
Author Profile
Balaji Rajendran

Centre for Development of Advanced Computing (C-DAC) Bengaluru 560100 India

India
Author Profile
P. V. Akshay

Centre for Development of Advanced Computing (C-DAC) Bengaluru 560100 India

India

📄 논문 정보

발행 연도 2024년
인용수 0
출판 국가 India
사이트 Springer
좋아요 수 0

연관 논문 목록 (55건)