A User-Centric Machine Learning Framework for Cyber Security Operations Center

被引:0
|
作者
Feng, Charles [1 ]
Wu, Shuning [2 ]
Liu, Ningwei [3 ]
机构
[1] ZhongDu Technol Inc, Shaoxing, Zhejiang, Peoples R China
[2] Symantec Corp, Ctr Adv Machine Learning, Mountain View, CA USA
[3] Symantec Corp, Norton Business Unit, Mountain View, CA USA
关键词
user-centric; machine learning system; cyber security operation center; risky user detection;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
To assure cyber security of an enterprise, typically SIEM (Security Information and Event Management) system is in place to normalize security events from different preventive technologies and flag alerts. Analysts in the security operation center (SOC) investigate the alerts to decide if it is truly malicious or not. However, generally the number of alerts is overwhelming with majority of them being false positive and exceeding the SOC's capacity to handle all alerts. Because of this, potential malicious attacks and compromised hosts may be missed. Machine learning is a viable approach to reduce the false positive rate and improve the productivity of SOC analysts. In this paper, we develop a user-centric machine learning framework for the cyber security operation center in real enterprise environment. We discuss the typical data sources in SOC, their work flow, and how to leverage and process these data sets to build an effective machine learning system. The paper is targeted towards two groups of readers. The first group is data scientists or machine learning researchers who do not have cyber security domain knowledge but want to build machine learning systems for security operations center. The second group of audiences are those cyber security practitioners who have deep knowledge and expertise in cyber security, but do not have machine learning experiences and wish to build one by themselves. Throughout the paper, we use the system we built in the Symantec SOC production environment as an example to demonstrate the complete steps from data collection, label creation, feature engineering, machine learning algorithm selection, model performance evaluations, to risk score generation.
引用
收藏
页码:173 / 175
页数:3
相关论文
共 50 条
  • [11] PERIMETER: A User-Centric Mobility Framework
    De Vogeleer, Karel
    Ickin, Selim
    Erman, David
    Fiedler, Markus
    [J]. IEEE LOCAL COMPUTER NETWORK CONFERENCE, 2010, : 625 - 626
  • [12] A User-Centric Threat Model and Repository for Cyber Attacks
    Datta, Prerit
    Sartoli, Sara
    Gutierrez, Luis Felipe
    Abri, Faranak
    Namin, Akbar Siami
    Jones, Keith S.
    [J]. 37TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, 2022, : 1341 - 1344
  • [13] The Design and Evaluation of a User-Centric Information Security Risk Assessment and Response Framework
    Alohali, Manal
    Clarke, Nathan
    Furnell, Steven
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2018, 9 (10) : 148 - 163
  • [14] User-Centric Cloud Framework for Enhanced Data Security by Applying UK Algorithm
    Umapathy, B.
    Kalpana, G.
    [J]. JOURNAL OF ELECTRICAL SYSTEMS, 2024, 20 (03) : 42 - 51
  • [16] Security, privacy and trust of user-centric solutions
    Akram, Raja Naeem
    Chen, Hsiao-Hwa
    Lopez, Javier
    Sauveron, Damien
    Yang, Laurence T.
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 80 : 417 - 420
  • [17] Designing User-Centric Explanations for Medical Imaging with Informed Machine Learning
    Oberste, Luis
    Rueffer, Florian
    Aydinguel, Okan
    Rink, Johann
    Heinzl, Armin
    [J]. DESIGN SCIENCE RESEARCH FOR A NEW SOCIETY: SOCIETY 5.0, DESRIST 2023, 2023, 13873 : 470 - 484
  • [18] A predictive and user-centric approach to Machine Learning in data streaming scenarios
    Carneiro, Davide
    Guimaraes, Miguel
    Silva, Fabio
    Novais, Paulo
    [J]. NEUROCOMPUTING, 2022, 484 : 238 - 249
  • [19] User-centric privacy framework for pervasive environments
    Bagues, Susana Alcalde
    Zeidler, Andreas
    Valdivielso, Carlos Fernandez
    Matias, Ignacio R.
    [J]. ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2006: OTM 2006 WORKSHOPS, PT 2, PROCEEDINGS, 2006, 4278 : 1347 - 1356
  • [20] A user-centric service framework for pervasive computing
    Zhu, Zhenmin
    Su, Xiaoli
    Li, Jintao
    Guo, Junbo
    Ye, Jian
    [J]. 2006 1ST INTERNATIONAL SYMPOSIUM ON PERVASIVE COMPUTING AND APPLICATIONS, PROCEEDINGS, 2006, : 42 - +