A User-Centric Machine Learning Framework for Cyber Security Operations Center

被引:0
|
作者
Feng, Charles [1 ]
Wu, Shuning [2 ]
Liu, Ningwei [3 ]
机构
[1] ZhongDu Technol Inc, Shaoxing, Zhejiang, Peoples R China
[2] Symantec Corp, Ctr Adv Machine Learning, Mountain View, CA USA
[3] Symantec Corp, Norton Business Unit, Mountain View, CA USA
关键词
user-centric; machine learning system; cyber security operation center; risky user detection;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
To assure cyber security of an enterprise, typically SIEM (Security Information and Event Management) system is in place to normalize security events from different preventive technologies and flag alerts. Analysts in the security operation center (SOC) investigate the alerts to decide if it is truly malicious or not. However, generally the number of alerts is overwhelming with majority of them being false positive and exceeding the SOC's capacity to handle all alerts. Because of this, potential malicious attacks and compromised hosts may be missed. Machine learning is a viable approach to reduce the false positive rate and improve the productivity of SOC analysts. In this paper, we develop a user-centric machine learning framework for the cyber security operation center in real enterprise environment. We discuss the typical data sources in SOC, their work flow, and how to leverage and process these data sets to build an effective machine learning system. The paper is targeted towards two groups of readers. The first group is data scientists or machine learning researchers who do not have cyber security domain knowledge but want to build machine learning systems for security operations center. The second group of audiences are those cyber security practitioners who have deep knowledge and expertise in cyber security, but do not have machine learning experiences and wish to build one by themselves. Throughout the paper, we use the system we built in the Symantec SOC production environment as an example to demonstrate the complete steps from data collection, label creation, feature engineering, machine learning algorithm selection, model performance evaluations, to risk score generation.
引用
收藏
页码:173 / 175
页数:3
相关论文
共 50 条
  • [1] RETRACTED ARTICLE: A User-Centric Machine Learning for Learning Support System with Adequate Cyber Security
    Fang Liu
    Juan Wang
    [J]. Wireless Personal Communications, 2022, 127 : 19 - 19
  • [2] RETRACTED: A User-Centric Machine Learning for Learning Support System with Adequate Cyber Security (Retracted Article)
    Liu, Fang
    Wang, Juan
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2022, 127 (SUPPL 1) : 19 - 19
  • [3] User-Centric Security
    Feth, Denis
    [J]. 2015 10TH JOINT MEETING OF THE EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND THE ACM SIGSOFT SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING (ESEC/FSE 2015) PROCEEDINGS, 2015, : 1034 - 1037
  • [4] User-centric Security and The Dynamic Enterprise
    Cosquer, F.
    [J]. ENRICHING COMMUNICATIONS, 2009, 3 (01): : 53 - 56
  • [5] RIFLE: An architectural framework for user-centric information-flow security
    Vachharajani, N
    Bridges, MJ
    Chang, J
    Rangan, R
    Ottoni, G
    Blome, JA
    Reis, GA
    Vachharajani, M
    August, DI
    [J]. MICRO-37 2004: 37TH ANNUAL INTERNATIONAL SYMPOSIUM ON MICROARCHITECTURE, PROCEEDINGS, 2004, : 243 - 254
  • [6] Expert-Informed, User-Centric Explanations for Machine Learning
    Pazzani, Michael
    Soltani, Severine
    Kaufman, Robert
    Qian, Samson
    Hsiao, Albert
    [J]. THIRTY-SIXTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTY-FOURTH CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE / TWELVETH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, : 12280 - 12286
  • [7] Online Learning Framework based on user-centric access behavior
    Huang, Guohao
    Jiang, Hao
    Xie, Jing
    Zeng, Yuanyuan
    Yi, Shuwen
    [J]. IEEE 20TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS / IEEE 16TH INTERNATIONAL CONFERENCE ON SMART CITY / IEEE 4TH INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2018, : 290 - 297
  • [8] SRAF: Scalable Resource Allocation Framework using Machine Learning in user-Centric Internet of Things
    Al-Makhadmeh, Zafer
    Tolba, Amr
    [J]. PEER-TO-PEER NETWORKING AND APPLICATIONS, 2021, 14 (04) : 2340 - 2350
  • [9] LiFi grid: a machine learning approach to user-centric design
    Pashazanoosi, Mohamadreza
    Nezamalhosseini, S. Alireza
    Salehi, Jawad A.
    [J]. APPLIED OPTICS, 2020, 59 (28) : 8895 - 8901
  • [10] SRAF: Scalable Resource Allocation Framework using Machine Learning in user-Centric Internet of Things
    Zafer Al-Makhadmeh
    Amr Tolba
    [J]. Peer-to-Peer Networking and Applications, 2021, 14 : 2340 - 2350