A USER-CENTRIC MACHINE LEARNING FRAMEWORK FORDIGITAL SECURITY OPERATIONS
Dr.M.sujatha S.Venkata Durga Prasad · Journal of Critical Reviews · 2020
To assure cyber security of an enterprise, typicallySIEM (Security Information and Event Management) system is inplace to normalize security events from different preventivetechnologies and flag alerts. Analysts in the security operationcentre (SOC) investigate the alerts to decide if it is truly maliciousor not. However, generally the number of alerts is overwhelmingcapacity to handle all alerts. Because of this, potential maliciousattacks and compromised hosts may be missed. Machine learningis a viable approach to reduce the false positive rate and improvethe productivity of SOC analysts. In this paper, we develop a usercentric machine learning framework for the cyber securityoperation centre in real enterprise environment. We discuss thetypical data sources in SOC, theirwork flow, and how to leverageand process these data sets to build an effective machine learningsystem. The paper is targeted towards two groups of readers. Thefirst group is data scientists or machine learning researchers whodo not have cyber security domain knowledge but want to buildmachine learning systems for security operations centre. Thesecond group of audiences are those cyber security practitionerswho have deep knowledge and expertise in cyber security, but donot have machine learning experiences and wish to build one bythemselves. Throughout the paper, we use the system we built inthe Symantec SOC production environment as an example todemonstrate the complete steps from data collection, labelcreation, feature engineering, machine learning algorithmselection, model performance evaluations, to risk score generation.