4.6 Article

Learning From Experts' Experience: Toward Automated Cyber Security Data Triage

期刊

IEEE SYSTEMS JOURNAL
卷 13, 期 1, 页码 603-614

出版社

IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
DOI: 10.1109/JSYST.2018.2828832

关键词

Automated system; cyber security analysis; data triage; knowledge elicitation; security operations center

资金

  1. ARO [W911NF-15-1-0576, W911NF-13-1-0421]
  2. NSF [CNS-1422594]
  3. IUK Grant-in Aid of Faculty Research and Summer Faculty Fellowship
  4. Direct For Computer & Info Scie & Enginr
  5. Division Of Computer and Network Systems [1422594] Funding Source: National Science Foundation

向作者/读者索取更多资源

Security operations centers (SOCs) employ various cyber defend measures to monitor network events. Apart from these measures, SOCs also have to resort to human analysts to make sense of the collected data for incident detection and response. However, with the oncoming network data collected and accumulated at a rapid speed, analysts are usually overwhelmed by tedious and repeated data triage tasks so that they can hardly concentrate on in-depth analysis to create timely and quality incident reports. This paper aims to reduce the analysts' workloads by developing data triage automatons. We have developed a computer-aided tracing method for capturing analysts' operations while they are performing a task. This paper proposes a graph-based trace mining approach for constructing useful patterns for data triage from the operation traces. Finite state machines can be constructed based on the rules to automate data triage. A human-in-the-loop case study is conducted to evaluate our approach, in which 30 professional analysts were recruited and asked to complete a cyber-analysis task with their operations being traced. State machines were constructed based on the traces and then the effectiveness of developing state machines and the performance of state machines are evaluated. The result shows that it is feasible to conduct automated data triage by leveraging analysts' traces. The state machines are able to complete processing a large amount of data within minutes. Comparing the performance of automated data triage with the ground truth, we found that a satisfactory false positive rate can be achieved.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.6
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据