返回
Testing SOAR tools in use
DOI:10.1016/j.cose.2023.103201.png)
摘要
En 中文
Investigations within Security Operation Centers (SOCs) are tedious as they rely on manual effort s to query diverse data sources, overlay related logs, correlate the data into information, and then document results in a ticketing system. Security Orchestration, Automation, and Response (SOAR) tools are a rela-tively new technology that promise, with appropriate configuration, to collect, filter, and display needed diverse information; automate many of the common tasks that unnecessarily require SOC analysts' time; facilitate SOC collaboration; and, in doing so, improve both efficiency and consistency of SOCs. There has been no prior research to test SOAR tools in practice; hence, understanding and evaluation of their ef-fect is nascent and needed. In this paper, we design and administer the first hands-on user study of SOAR tools, involving 24 participants and six commercial SOAR tools. Our contributions include the ex-perimental design, itemizing six defining characteristics of SOAR tools, and a methodology for testing them. We describe configuration of a cyber range test environment, including network, user, and threat emulation; a full SOC tool suite; and creation of artifacts allowing multiple representative investigation scenarios to permit testing. We present the first research results on SOAR tools. Concisely, our findings are that: per-SOC SOAR configuration is extremely important; SOAR tools increase efficiency and reduce context switching, although with potentially decreased ticketing accuracy/completeness; user preference is slightly negatively correlated with their performance with the tool; internet dependence varies widely among SOAR tools; and balance of automation with assisting decision making is preferred by senior par-ticipants. We deliver a public user-and tool-anonymized and-obfuscated version of the data.(c) 2023 Elsevier Ltd. All rights reserved.
Keyword:
Security orchestration automation and
response (SOAR)
Test and evaluation
User study
Security operation center (SOC)
Cybersecurity technology
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
Intrinsic Properties and Future Perspective of HfO2/V2O5/HfO2 Multi-Layer Thin Films via E-Beam Evaporation as a Transparent Heat Mirror
Coatings
IF0

