首页    期刊浏览 2025年06月26日 星期四
登录注册

文章基本信息

  • 标题:A comprehensive security operation center based on big data analytics and threat intelligence
  • 本地全文:下载
  • 作者:J.Wang ; T.Yan ; D.An
  • 期刊名称:PoS - Proceedings of Science
  • 印刷版ISSN:1824-8039
  • 出版年度:2021
  • 卷号:378
  • DOI:10.22323/1.378.0028
  • 语种:English
  • 出版社:SISSA, Scuola Internazionale Superiore di Studi Avanzati
  • 摘要:The continued growth of cybersecurity incidents calls for effective cybersecurity monitoring solutions. The operation of security operation centers (SOCs) is the recommended best practice to which large and medium-size organizations rely for the detection, notification, and ultimately response to cybersecurity incidents. However, current SOCs face several issues, such as inferior defense against specific types of attacks, low-quality threat intelligence, low speed of response and low level of automation. In this paper, a comprehensive SOC is introduced to mitigate above mentioned issues of current SOCs. First, the SOC collects a wide variety of data including network traffic, server logs, security incidents logs. The collected data is preprocessed and stored in a big-data storage platform. Secondly, the SOC provides multi-perspective behavior analysis which can combine the detection performance of multiple behavior detectors. Different detectors can analyze different and specific types of attack based on the data on the big data storage platform. Besides, threat intelligence is collected accurately from unstructured open-source cyber threat intelligence reports by using deep learning model and is correlated with incidents detection to identify attacks rapidly. Finally, the SOC can uniformly manage and automatically respond the incidents identified from multi-perspective behavior analysis and threat intelligence. At the same time, visualization is adopted to reveal the cybersecurity situation of entire organizations. The framework of the SOC is derived from the CERN design, and is customized to make it is practical and deployable for the Institute of High Energy Physics to discover, identify, understand, analyze, and respond to cybersecurity incidents from a comprehensive perspective.
国家哲学社会科学文献中心版权所有