Searched for: subject%3A%22SoC%22
(1 - 2 of 2)
document
Vermeer, M. (author), Kadenko, N.I. (author), van Eeten, M.J.G. (author), Hernandez Ganan, C. (author), Parkin, S.E. (author)
Signature-based network intrusion detection systems (NIDSs) and network intrusion prevention systems (NIPSs) remain at the heart of network defense, along with the rules that enable them to detect threats. These rules allow Security Operation Centers (SOCs) to properly defend a network, yet we know almost nothing about how rules are created,...
conference paper 2023
document
Chiba, Daiki (author), Akiyama, Mitsuaki (author), Otsuki, Yuto (author), Hada, Hiroki (author), Yagi, Takeshi (author), Fiebig, Tobias (author), van Eeten, M.J.G. (author)
Security Operations Centers (SOCs) are in need of automation for triaging alerts. Current approaches focus on analyzing and enriching individual alerts. We take a different approach and analyze the population of alerts. In an observational study over 24 weeks, we find a surprising pattern: some domains get analyzed again and again by different...
journal article 2022