arrow
Return

Testing SOAR tools in use

delete2023-06-01
delete4
delete
OA
AI
R
Robert A. Bridges *
A
Ashley E. Rice
S
Sean Oesch
J
Jeffrey A. Nichols
C
Cory Watson
K
Kevin Spakes
S
Savannah Norem
M
Mike Huettel
B
Brian Jewell
B
Brian Weber
C
Connor Gannon
O
Olivia Bizovi
S
Samuel C. Hollifield
S
Samantha Erwin
DOI:10.1016/j.cose.2023.103201delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Investigations within Security Operation Centers (SOCs) are tedious as they rely on manual effort s to query diverse data sources, overlay related logs, correlate the data into information, and then document results in a ticketing system. Security Orchestration, Automation, and Response (SOAR) tools are a rela-tively new technology that promise, with appropriate configuration, to collect, filter, and display needed diverse information; automate many of the common tasks that unnecessarily require SOC analysts' time; facilitate SOC collaboration; and, in doing so, improve both efficiency and consistency of SOCs. There has been no prior research to test SOAR tools in practice; hence, understanding and evaluation of their ef-fect is nascent and needed. In this paper, we design and administer the first hands-on user study of SOAR tools, involving 24 participants and six commercial SOAR tools. Our contributions include the ex-perimental design, itemizing six defining characteristics of SOAR tools, and a methodology for testing them. We describe configuration of a cyber range test environment, including network, user, and threat emulation; a full SOC tool suite; and creation of artifacts allowing multiple representative investigation scenarios to permit testing. We present the first research results on SOAR tools. Concisely, our findings are that: per-SOC SOAR configuration is extremely important; SOAR tools increase efficiency and reduce context switching, although with potentially decreased ticketing accuracy/completeness; user preference is slightly negatively correlated with their performance with the tool; internet dependence varies widely among SOAR tools; and balance of automation with assisting decision making is preferred by senior par-ticipants. We deliver a public user-and tool-anonymized and-obfuscated version of the data.(c) 2023 Elsevier Ltd. All rights reserved.
Keywords:
Security orchestration automation and
response (SOAR)
Test and evaluation
User study
Security operation center (SOC)
Cybersecurity technology
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

U
united states department of energy (doe)
Scholars:
11.3W
Papers: 9.6W
Citations: 246
O
oak ridge national laboratory
Scholars:
1.4W
Papers: 1.0W
Citations: 20