SOC Use Cases: Deployment, Challenges and Gap Assessment Based on MITRE ATT&CK
摘要
The increasing number and sophistication of cybersecurity threats nowadays demand constant vigilance and rapid response capabilities as the stakes for protecting digital assets are higher than ever. As a result, we have a widespread adoption of SOCs (Security Operations Centers) by companies across different sectors to afford an effective, highly focused resource for detecting and responding actively to cybersecurity incidents. The purpose is to clearly define the SOC′s objectives and scope and choose the right technologies, cybersecurity professional, and SOC analysts while developing and documenting processes for the SOC lifecycle. Choosing the right technologies and ensuring they integrate well with companies’ existing IT infrastructure and device products and vendors list is particularly important for the SOC scope coverage definition when defining the SOC security monitoring of the use cases definition. This study aims at analysing the SOC technical coverage and using the application of the MITRE ATT&CK framework for tactics and techniques to check for loopholes in detection rules with respect to the organization′s existent security technologies.