Machine Learning for Threat Detection in SOCs
Ema Josipovic, Damir Regvart, Ana Kapulica, Robert Kopal · Annals of DAAAM for ... & proceedings of the ... International DAAAM Symposium · 2024
This paper explores the integration of Machine Learning (ML) algorithms within Security Operations Centres (SOCs) for enhanced cyber threat detection.It examines the effectiveness of various ML algorithms, such as Random Forest and SVM, in identifying and mitigating cyber threats.The paper delves into the inherent challenges associated with ML in cybersecurity, including vulnerabilities to adversarial attacks and issues of overfitting.Strategies to overcome these challenges are discussed, highlighting the importance of advanced data handling and the necessity of human expertise alongside ML.The paper concludes by emphasizing the transformative potential of ML in cybersecurity, advocating for continuous innovation and ethical considerations in its application.