中文
相关论文

相关论文: Decision-Aware Trust Signal Alignment for SOC Aler…

200 篇论文

Enterprise networks are growing ever larger with a rapidly expanding attack surface, increasing the volume of security alerts generated from security controls. Security Operations Centre (SOC) analysts triage these alerts to identify…

密码学与安全 · 计算机科学 2025-05-16 Melissa Turcotte , François Labrèche , Serge-Olivier Paquette

Security Operations Centers (SOCs) are pivotal in modern enterprises. Tasked to monitor complex network environments constantly under attack, SOCs can be active 24/7 and can include hundreds of operators supported by state-of-the-art…

密码学与安全 · 计算机科学 2026-04-27 Jessica Moosmann , Irdin Pekaric , Giovanni Apruzzese

Several real-world classification problems are example-dependent cost-sensitive in nature, where the costs due to misclassification vary between examples and not only within classes. However, standard classification methods do not take…

机器学习 · 计算机科学 2015-05-19 Alejandro Correa Bahnsen , Djamila Aouada , Bjorn Ottersten

To assure cyber security of an enterprise, typically SIEM (Security Information and Event Management) system is in place to normalize security event from different preventive technologies and flag alerts. Analysts in the security operation…

密码学与安全 · 计算机科学 2018-01-03 Wangyan Feng , Shuning Wu , Xiaodan Li , Kevin Kunkle

Security Operations Centers (SOCs) are overwhelmed by tens of thousands of daily alerts, with only a small fraction corresponding to genuine attacks. This overload creates alert fatigue, leading to overlooked threats and analyst burnout.…

计算与语言 · 计算机科学 2025-10-02 Bowen Wei , Yuan Shen Tay , Howard Liu , Jinhao Pan , Kun Luo , Ziwei Zhu , Chris Jordan

Security alert screening is the downstream task of filtering, prioritizing, correlating, and contextualizing alerts for analyst attention in Security Operations Centers. This survey reviews artificial-intelligence-driven alert screening and…

密码学与安全 · 计算机科学 2026-05-20 Samuel Ndichu , Tao Ban , Seiichi Ozawa , Takeshi Takahashi , Daisuke Inoue

Security operation centers (SOCs) all over the world are tasked with reacting to cybersecurity alerts ranging in severity. Security Orchestration, Automation, and Response (SOAR) tools streamline cybersecurity alert responses by SOC…

人机交互 · 计算机科学 2021-12-02 Savannah Norem , Ashley E Rice , Samantha Erwin , Robert A Bridges , Sean Oesch , Brian Weber

Automation in Security Operations Centers (SOCs) plays a prominent role in alert classification and incident escalation. However, automated methods must be robust in the presence of imbalanced input data, which can negatively affect…

密码学与安全 · 计算机科学 2025-07-03 Koen T. W. Teuwen , Sam Baggen , Emmanuele Zambon , Luca Allodi

"Alert fatigue" is one of the biggest challenges faced by the Security Operations Center (SOC) today, with analysts spending more than half of their time reviewing false alerts. Endpoint detection products raise alerts by pattern matching…

密码学与安全 · 计算机科学 2024-05-09 Jonathan Oliver , Raghav Batta , Adam Bates , Muhammad Adil Inam , Shelly Mehta , Shugao Xia

High-quality system-level message flow specifications are necessary for comprehensive validation of system-on-chip (SoC) designs. However, manual development and maintenance of such specifications are daunting tasks. We propose a disruptive…

人工智能 · 计算机科学 2022-09-19 Md Rubel Ahmed , Bardia Nadimi , Hao Zheng

With the growing number of devices, sensors and digital systems, data logs may become uncertain due to, e.g., sensor reading inaccuracies or incorrect interpretation of readings by processing programs. At times, such uncertainties can be…

人工智能 · 计算机科学 2023-11-22 Eli Bogdanov , Izack Cohen , Avigdor Gal

As large language models (LLMs) are increasingly deployed in critical decision-making systems, the lack of reliable methods to measure their uncertainty presents a fundamental trustworthiness risk. We introduce a normalized confidence score…

机器学习 · 计算机科学 2026-03-10 Xie Xiaohu , Liu Xiaohu , Yao Benjamin

Probabilistic security assessment and real-time dynamic security assessments (DSA) are promising to better handle the risks of system operations. The current methodologies of security assessments may require many time-domain simulations for…

系统与控制 · 电气工程与系统科学 2023-01-06 Jochen L. Cremer , Goran Strbac

Alert correlation is a system which receives alerts from heterogeneous Intrusion Detection Systems and reduces false alerts, detects high level patterns of attacks, increases the meaning of occurred incidents, predicts the future states of…

密码学与安全 · 计算机科学 2018-11-05 Seyed Ali Mirheidari , Sajjad Arshad , Rasool Jalili

This paper considers the design of tunable decision schemes capable of rejecting with high probability mismatched signals embedded in Gaussian interference with unknown covariance matrix. To this end, a sparse recovery technique is…

信号处理 · 电气工程与系统科学 2020-04-29 Sudan Han , Luca Pallotta , Xiaotao Huang , Gaetano Giunta , Danilo Orlando

With frequently evolving Advanced Persistent Threats (APTs) in cyberspace, traditional security solutions approaches have become inadequate for threat hunting for organizations. Moreover, SOC (Security Operation Centers) analysts are often…

This work considers the problem of detecting signals from multiple sequentially observed data streams, where only one stream can be observed at every time instant. The goal is to detect signals as quickly as possible while controlling the…

统计方法学 · 统计学 2026-04-07 Yiming Xing , Georgios Fellouris

Many Security Operations Centers (SOCs) today still heavily rely on signature-based Network Intrusion Detection Systems (NIDS) such as Suricata. The specificity of intrusion detection rules and the coverage provided by rulesets are common…

密码学与安全 · 计算机科学 2025-01-20 Koen T. W. Teuwen , Tom Mulders , Emmanuele Zambon , Luca Allodi

This article presents a structured framework for Human-AI collaboration in Security Operations Centers (SOCs), integrating AI autonomy, trust calibration, and Human-in-the-loop decision making. Existing frameworks in SOCs often focus…

人工智能 · 计算机科学 2025-06-03 Ahmad Mohsin , Helge Janicke , Ahmed Ibrahim , Iqbal H. Sarker , Seyit Camtepe

Intrusion Detection is an invaluable part of computer networks defense. An important consideration is the fact that raising false alarms carries a significantly lower cost than not detecting at- tacks. For this reason, we examine how…

密码学与安全 · 计算机科学 2008-07-15 Aikaterini Mitrokotsa , Christos Dimitrakakis , Christos Douligeris
‹ 上一页 1 2 3 10 下一页 ›