Comprehending security events: context-based identification and explanation
Thijs van Ede · 2023
With the increased sophistication of cyber attacks, organizations are under constant threat of data breaches, disruption of business processes and reputation loss.As preventive measures are not infallible, organizations have started to more closely monitor their devices and network infrastructure for malicious activity.By swift detection of an attack at an early stage, organizations can take mitigating actions limiting the impact to their organization.This detection can be done internally or is outsourced to a Security Operations Center (SOC).The SOC deploys automated detectors that monitor devices and network traffic for suspicious events, which are subsequently sent to the SOC.Here, security operators manually analyze these events, verify whether they constitute an attack and, if required, take action.Analyzing security events is not straightforward and requires highly skilled operators.We identified three major challenges that operators face during analysis: Contents 5.7 Discussion and Future Work . . . . . .