Publication:
Intelligent SOC Chatbot for Security Operation Center

dc.contributor.authorPerera, V. H
dc.contributor.authorSenarathne, A. N
dc.contributor.authorRupasinghe, L
dc.date.accessioned2022-03-22T06:55:03Z
dc.date.available2022-03-22T06:55:03Z
dc.date.issued2019-12-05
dc.description.abstractInformation security analysts currently face many challenges: both hidden and visible in the face of unique attack records. The rapid increase patterns of security monitoring and investigation tools (as an average of 20 security solutions have been used per company) leads to frequent changing between screens, alert fatigue, disjointed record keeping, and increased investigation time. This chatbot can suggest the flow of investigation and the relevant commands that will help to obtain the results which need to be resolved the incident. Automate the incident ticket creation is one of major achievement of this research. Security analysts also receive messages of security alerts of the AWS hosted instances. Security analysts are also continuing to work on their sub tasks, quite overloaded with their main tasks to engage in collaborative investigations and knowledge sharing. Chat-Ops help to vanquish and meet those challenges. Processes, automated workflows, the chatbot, security tools, and humans exist in the same chat window feeding data and commands in a worthy cycle. It will lead to huge changes in everything from remediation times and investigation depth to future learning and knowledge administration. Different analysts will drive the investigation in different ways. Most of the time, analysts will miss most important parts and techniques, but those parts could be very valuable for the result. The investigation flow and commands will suggest based on past investigations and commands that previous analysts were used. This chatbot will help in many ways of current analyst who work in a security operation center.en_US
dc.identifier.citationV. H. Perera, A. N. Senarathne and L. Rupasinghe, "Intelligent SOC Chatbot for Security Operation Center," 2019 International Conference on Advancements in Computing (ICAC), 2019, pp. 340-345, doi: 10.1109/ICAC49085.2019.9103388.en_US
dc.identifier.doi10.1109/ICAC49085.2019.9103388en_US
dc.identifier.isbn978-1-7281-4170-1
dc.identifier.urihttps://rda.sliit.lk/handle/123456789/1742
dc.language.isoenen_US
dc.publisherIEEEen_US
dc.relation.ispartofseries2019 International Conference on Advancements in Computing (ICAC);Pages 340-345
dc.subjectIntelligent SOCen_US
dc.subjectSOC Chatboten_US
dc.subjectSecurity Operationen_US
dc.subjectOperation Centeren_US
dc.titleIntelligent SOC Chatbot for Security Operation Centeren_US
dc.typeArticleen_US
dspace.entity.typePublication

Files

Original bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
Intelligent_SOC_Chatbot_for_Security_Operation_Center.pdf
Size:
410.02 KB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: