Abstract
As Information Technology (IT) infrastructures have become increasingly complex to secure against accelerating cyber threats, current threat detection approaches have been largely silos in nature; security analysts in the environment are typically bombarded with large volume of security alerts that often cause severe fatigues and the possibility of judgement errors. This problem is further exacerbated by the number of false-positives that analysts may waste valuable time and resources pursuing. In this paper, we present how intuitive graph-based machine learning can be used to address the problem of alert fatigue and prioritize risky alerts to assist security analysts. The rationale and workflow of the proposed Graph Analysis (GA) algorithm is discussed in detail, with its effectiveness demonstrated by simulated experiments.
Author supplied keywords
Cite
CITATION STYLE
Meng, Q., Oo, N., Lim, H. W., & Sikdar, B. (2023). POSTER: Security Logs Graph Analytics for Industry Network System. In Proceedings of the ACM Conference on Computer and Communications Security (pp. 1043–1045). Association for Computing Machinery. https://doi.org/10.1145/3579856.3592830
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.