错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Leveraging Tech Towards Keeping Ahead of Cyber Threats and Alleviating Security Analysts’ Alert Fatigue

  • Sruthi Soman,
  • Zoheir Ezziane

摘要

When talking about the various domains in information security, incident response is one of the domains that many organisations fail to implement properly. Among the multiple challenges that contribute to the below-par state of incident response, alert fatigue has been often regarded as the elephant in the room. The strain on cybersecurity teams is great in the fast-paced world of cybersecurity, where risks lurk around every turn. They are the defenders and protectors of our digital strongholds. However, as much as we rely on these specialists to keep us safe, as well as understand the strain they are under alert fatigue is one particular issue that exacerbates this stress. This research project aims to tackle the problem created by the rapid growth of technology utilising the recent technological advancements in AI and modern-age cyber tools. The best outcome of this research is obtained by leveraging automation, machine learning, and the latest cyber software to tackle the alerts, triage them, and use human intervention at the first level of cyber security operations canter minimal. The initial research done to determine the factors leading to inefficient processing of alerts was successful and forms the primary input to the research. Various best practices that can be followed by organisations are researched with multiple potential options being laid out to cater for organisations of varying size and capital at their disposal.