Development of a Universal High-Performance Machine Learning Framework for Finding Cybersecurity Anomalies in Big Data
摘要
The main aim of the investigation is to simplify the day-to-day operations at Cyber Security Operations Center (CSOC). The management of an array of cybersecurity tools, such as Intrusion Detection System (IDS), Endpoint Detection and Response (EDR), Next-Generation Firewall (NGFW), Data Loss Prevention (DLP), and Cloud Access Security Broker (CASB) poses a great challenge for CSOC. Additionally, there is a massive inflow of raw data from various systems and applications that adds up to this problem. This circumstance puts significant stress on CSOC analysts resulting in mishandling events, delayed response times, longer duration event processing timeframes along generating false alarms furthermore adding more complexities. Two pragmatic alternatives are available to effectively solve these problems: Increase CSOC funding by hiring additional analysts or making it more difficult to identify and respond to anomalies.