论文标题

建立有效的网络安全操作中心的挑战

Challenges towards Building an effective Cyber Security Operations Centre

论文作者

Onwubiko, Cyril, Ouazzane, Karim

论文摘要

现代社会对IT系统和基础设施对基本服务的依赖性日益增加(例如互联网银行,车辆网络,健康状况等),以及越来越多的网络事件和安全漏洞使网络安全操作中心(CSOC)无疑至关重要。由于此类安全操作监视现在是大多数业务运营不可或缺的一部分。 SOC(互换为CSOC)负责连续和保护性监控业务服务,IT系统和基础设施,以识别漏洞,检测网络攻击,安全违规,违反政策,并迅速响应网络事件。他们还必须确保对安全事件和警报进行分类和分析,同时协调和管理网络事件以解决。由于SOC至关重要,因此SOC也有效。但是不幸的是,SOC的有效性是普遍关注的问题,也是无限辩论的重点。在本文中,我们确定并讨论建立有效SOC的一些相关挑战。我们研究了导致SOC效率低下的一些因素,并解释了他们面临的一些挑战。此外,我们提供并确定建议解决确定的问题。

The increasing dependency of modern society on IT systems and infrastructures for essential services (e.g. internet banking, vehicular network, health-IT, etc.) coupled with the growing number of cyber incidents and security vulnerabilities have made Cyber Security Operations Centre (CSOC) undoubtedly vital. As such security operations monitoring is now an integral part of most business operations. SOCs (used interchangeably as CSOCs) are responsible for continuously and protectively monitoring business services, IT systems and infrastructures to identify vulnerabilities, detect cyber-attacks, security breaches, policy violations, and to respond to cyber incidents swiftly. They must also ensure that security events and alerts are triaged and analysed, while coordinating and managing cyber incidents to resolution. Because SOCs are vital, it is also necessary that SOCs are effective. But unfortunately, the effectiveness of SOCs are a widespread concern and a focus of boundless debate. In this paper, we identify and discuss some of the pertinent challenges to building an effective SOC. We investigate some of the factors contributing to the inefficiencies in SOCs and explain some of the challenges they face. Further, we provide and prioritise recommendations to addressing the identified issues.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源