Publication:
Autosoc: A low budget flexible security operations platform for enterprises and organizations

dc.contributor.authorChamiekara, G. W. P
dc.contributor.authorCooray, M. I. M
dc.contributor.authorWickramasinghe, L. S. A. M
dc.contributor.authorKoshila, Y. M. S
dc.contributor.authorAbeywardhana, K. Y
dc.contributor.authorSenarathna, A. N
dc.date.accessioned2022-04-26T10:20:27Z
dc.date.available2022-04-26T10:20:27Z
dc.date.issued2017-09-14
dc.description.abstractMost of today's existing Security Operations Center (SOC) platforms follow a hybrid methodology in Security operations execution. However, these systems consist of a number of drawbacks. As there is a human component, there is a possibility of identification of false positives as true threat alerts. This will impact inversely towards the overall system. Currently there exists some automated SOCs as well, however their cost is considerably high for most small and medium scale companies. That is why we propose AutoSOC, a fully automated security operations center platform except for the Forensic investigation system, which requires a ticket to be generated with the approval of the user. This low budget enterprise solution comprises of an Intelligent Intrusion Detection and Prevention System (IIDPS), a Security Incident and Event Management System (SIEM), a Malware Analysis System and a Simple Forensic Investigation System. The Intelligent IIDPS contains an Intelligent Intrusion Detection System (IIDS) and an Intelligent Intrusion Prevention System (IIPS). IIDS is an alert system, which comprises components that notify and communicate in between integrated components when an attack or a breach occurs. The IIPS will understand the behavior of applications, and protocols are supposed to be according to their published standards. The SIEM is responsible for analyzing security event data, and it collects logs, stores, analyzes and reports on log data for incident response, forensics and regulatory compliance. The malware analysis process runs parallel to a forensic toolkit in order to accurately predict possible root causes for a certain incident. The forensic toolkit targets on the key components of analysis including processes running, packets captured etc. Therefore, the suggested solution will be able to reduce the cost of security implementations, increase the efficiency and accuracy of analysis results by eliminating false positives or the reporting of incorrect vulnerabilities by learning about the SOC network and environment.en_US
dc.identifier.citationG. W. P. Chamiekara, M. I. M. Cooray, L. S. A. M. Wickramasinghe, Y. M. S. Koshila, K. Y. Abeywardhana and A. N. Senarathna, "AutoSOC: A low budget flexible security operations platform for enterprises and organizations," 2017 National Information Technology Conference (NITC), 2017, pp. 100-105, doi: 10.1109/NITC.2017.8285644.en_US
dc.identifier.doi10.1109/NITC.2017.8285644en_US
dc.identifier.isbn978-1-5386-2425-8
dc.identifier.urihttps://rda.sliit.lk/handle/123456789/2076
dc.language.isoenen_US
dc.publisherIEEEen_US
dc.relation.ispartofseries2017 National Information Technology Conference (NITC);Pages 100-105
dc.subjectAutoSOCen_US
dc.subjectlow budgeten_US
dc.subjectflexible securityen_US
dc.subjectoperations platformen_US
dc.subjectenterprisesen_US
dc.subjectorganizationsen_US
dc.titleAutosoc: A low budget flexible security operations platform for enterprises and organizationsen_US
dc.typeArticleen_US
dspace.entity.typePublication

Files

Original bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
AutoSOC_A_low_budget_flexible_security_operations_platform_for_enterprises_and_organizations.pdf
Size:
381.23 KB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: