Reinforcement learning-based alert prioritisation in security operation centre: A framework for enhancing cybersecurity in the digital economy

R. Rani, Gregory Epiphaniou, Carsten R. Maple · IET conference proceedings. · 2023

We are in the middle of the digital revolution, a primary future driver for the UK economy. A digital exchange may face several cyber security challenges; one is the alert prioritisation to detect and resolve threats in the early stage and normalise the services. In this paper, we explore using Reinforcement Learning (RL) to prioritise the alerts in an organisation's Security Operation Centre (SOC). A SOC undertakes several tasks, such as identification, prioritisation, and classification of alerts. Prioritising the most critical alerts is increasingly challenging, in the heap of incoming alerts. An RL-based method can resolve this issue by automatically learning alert characteristics and prioritisation while minimising the SOC analysts' time and overhead. RL is the foundation of this use case in identifying and prioritising the alerts based on their characteristics. This paper first discusses the need for automatic alert prioritisation in SOC, followed by some background about the RL algorithm and manual handling of alerts in a SOC. Furthermore, the authors suggest a use-case of RL-based alert prioritisation in SOC. Moreover, this work also shows simulation results performed over a created synthetic dataset with an accuracy of 36.66%. Additionally, we also discuss the role of SOC in the digital economy. In the end, the paper concludes by suggesting some recommendations that can be useful in improving the accuracy of RL agents in correctly assigning priorities to the alerts.

Read the paper · More papers on PaperTik