That Escalated Quickly: An ML Framework for Alert Prioritization

02/13/2023
by   Ben Gelman, et al.
0

In place of in-house solutions, organizations are increasingly moving towards managed services for cyber defense. Security Operations Centers are specialized cybersecurity units responsible for the defense of an organization, but the large-scale centralization of threat detection is causing SOCs to endure an overwhelming amount of false positive alerts – a phenomenon known as alert fatigue. Large collections of imprecise sensors, an inability to adapt to known false positives, evolution of the threat landscape, and inefficient use of analyst time all contribute to the alert fatigue problem. To combat these issues, we present That Escalated Quickly (TEQ), a machine learning framework that reduces alert fatigue with minimal changes to SOC workflows by predicting alert-level and incident-level actionability. On real-world data, the system is able to reduce the time it takes to respond to actionable incidents by 22.9%, suppress 54% of false positives with a 95.1% detection rate, and reduce the number of alerts an analyst needs to investigate within singular incidents by 14%.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/03/2018

Adversarial Attack Type I: Generating False Positives

False positive and false negative rates are equally important for evalua...
research
08/09/2017

ChromaTag: A Colored Marker and Fast Detection Algorithm

Current fiducial marker detection algorithms rely on marker IDs for fals...
research
05/19/2021

Hunter in the Dark: Discover Anomalous Network Activity Using Deep Ensemble Network

Machine learning (ML)-based network intrusion detection system (NIDS) pl...
research
02/24/2018

Toward an Evidence-based Design for Reactive Security Policies and Mechanisms

As malware, exploits, and cyber-attacks advance over time, so do the mit...
research
04/30/2019

Detecting Reflections by Combining Semantic and Instance Segmentation

Reflections in natural images commonly cause false positives in automate...
research
12/13/2015

Building and Measuring Privacy-Preserving Predictive Blacklists

Collaborative security initiatives are increasingly often advocated to i...
research
08/24/2023

Towards Automated Animal Density Estimation with Acoustic Spatial Capture-Recapture

Passive acoustic monitoring can be an effective way of monitoring wildli...

Please sign up or login with your details

Forgot password? Click here to reset