A Mathematical Framework for Evaluation of SOAR Tools with Limited Survey Data

11/30/2021
by   Savannah Norem, et al.
0

Security operation centers (SOCs) all over the world are tasked with reacting to cybersecurity alerts ranging in severity. Security Orchestration, Automation, and Response (SOAR) tools streamline cybersecurity alert responses by SOC operators. SOAR tool adoption is expensive both in effort and finances. Hence, it is crucial to limit adoption to those most worthwhile; yet no research evaluating or comparing SOAR tools exists. The goal of this work is to evaluate several SOAR tools using specific criteria pertaining to their usability. SOC operators were asked to first complete a survey about what SOAR tool aspects are most important. Operators were then assigned a set of SOAR tools for which they viewed demonstration and overview videos, and then operators completed a second survey wherein they were tasked with evaluating each of the tools on the aspects from the first survey. In addition, operators provided an overall rating to each of their assigned tools, and provided a ranking of their tools in order of preference. Due to time constraints on SOC operators for thorough testing, we provide a systematic method of downselecting a large pool of SOAR tools to a select few that merit next-step hands-on evaluation by SOC operators. Furthermore, the analyses conducted in this survey help to inform future development of SOAR tools to ensure that the appropriate functions are available for use in a SOC.

READ FULL TEXT

page 14

page 15

research
10/11/2021

A Mutation Framework for Evaluating Security Analysis tools in IoT Applications

With the growing and widespread use of Internet of Things (IoT) in our d...
research
01/27/2021

Systematic Evaluation and Usability Analysis of Formal Tools for System Design

Formal methods and supporting tools have a long record of successes in t...
research
08/12/2022

Testing SOAR Tools in Use

Modern security operation centers (SOCs) rely on operators and a tapestr...
research
05/30/2022

Transparency, Governance and Regulation of Algorithmic Tools Deployed in the Criminal Justice System: a UK Case Study

We present a survey of tools used in the criminal justice system in the ...
research
12/16/2020

An Assessment of the Usability of Machine Learning Based Tools for the Security Operations Center

Gartner, a large research and advisory company, anticipates that by 2024...
research
12/05/2017

Simulating Opportunistic Networks: Survey and Future Directions

Simulation is one of the most powerful tools we have for evaluating the ...
research
01/18/2021

SoK: Fully Homomorphic Encryption Compilers

Fully Homomorphic Encryption (FHE) allows a third party to perform arbit...

Please sign up or login with your details

Forgot password? Click here to reset