Matched and Mismatched SOCs: A Qualitative Study on Security Operations Center Issues
Faris Bugra Kokulu, Ananta Soneji, Tiffany Bao, Yan Shoshitaishvili, Ziming Zhao, Adam Doupé, Gail-Joon Ahn
Abstract
Organizations, such as companies and governments, created Security Operations Centers (SOCs) to defend against computer security attacks. SOCs are central defense groups that focus on security incident management with capabilities such as monitoring, preventing, responding, and reporting. They are one of the most critical defense components of a modern organization's defense.
Despite their critical importance to organizations, and the high frequency of reported security incidents, only a few research studies focus on problems specific to SOCs. In this study, to understand and identify the issues of SOCs, we conducted 18 semi-structured interviews with SOC analysts and managers who work for organizations from different industry sectors. Through our analysis of the interview data, we identified technical and non-technical issues that exist in SOC. Moreover, we found inherent disagreements between SOC managers and their analysts that, if not addressed, could entail a risk to SOC efficiency and effectiveness. We distill these issues into takeaways that apply both to future academic research and to SOC management. We believe that research should focus on improving the efficiency and effectiveness of SOCs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 16ec6358-3872-4fd1-a19c-283d238ce9a5Cited by top-tier papers19
- DEEPCASE: Semi-Supervised Contextual Analysis of Security EventsThijs van Ede, Hojjat Aghakhani, Noah Spahn, Riccardo Bortolameotti et al.S&P 2022 · 91 citations
- Examining the Efficacy of Decoy-based and Psychological Cyber DeceptionKimberly Ferguson-Walter, Maxine Major, Chelsea K. Johnson, Daniel H. MuhlemanUSENIX Security 2021 · 52 citations
- Point Cloud Analysis for ML-Based Malicious Traffic Detection: Reducing Majorities of False Positive AlarmsChuanpu Fu, Qi Li, Ke Xu, Jianping WuCCS 2023 · 30 citations
- A Case Study of Phishing Incident Response in an Educational OrganizationKholoud Althobaiti, Adam D. G. Jenkins, Kami VanieaCSCW 2021 · 25 citations
- Burnout in Cybersecurity Incident Responders: Exploring the Factors that Light the FireSubigya Nepal, Javier Hernandez, Robert Lewis, Ahad Chaudhry et al.CSCW 2024 · 20 citations
Builds on5
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- Acing the IOC Game: Toward Automatic Discovery and Analysis of Open-Source Cyber Threat IntelligenceXiaojing Liao, Kan Yuan, XiaoFeng Wang, Zhou Li et al.CCS 2016 · 308 citations
- Investigating System Operators' Perspective on Security MisconfigurationsConstanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias FiebigCCS 2018 · 116 citations
- SoK: Science, Security and the Elusive Goal of Security as a Scientific PursuitCormac Herley, Paul C. van OorschotS&P 2017 · 95 citations
- The Battle for New York: A Case Study of Applied Digital Threat Modeling at the Enterprise LevelRock Stevens, Daniel Votipka, Elissa M. Redmiles, Colin Ahern et al.USENIX Security 2018 · 51 citations
Related papers
- Alert Alchemy: SOC Workflows and Decisions in the Management of NIDS RulesMathew Vermeer, Natalia Kadenko, Michel van Eeten, Carlos Gañán et al.CCS 2023 · 16 citations
- Work-From-Home and COVID-19: Trajectories of Endpoint Security Management in a Security Operations CenterKailani R. Jones, Dalton A. Brucker-Hahn, Bradley Fidler, Alexandru G. BardasUSENIX Security 2023
- True Attacks, Attack Attempts, or Benign Triggers? An Empirical Measurement of Network Alerts in a Security Operations CenterLimin Yang, Zhi Chen, Chenkai Wang, Zhenning Zhang et al.USENIX Security 2024 · 16 citations
- 99% False Positives: A Qualitative Study of SOC Analysts' Perspectives on Security AlarmsBushra A. AlAhmadi, Louise Axon, Ivan MartinovicUSENIX Security 2022
- "Employees Who Don't Accept the Time Security Takes Are Not Aware Enough": The CISO View of Human-Centred SecurityJonas Hielscher, Uta Menges, Simon Parkin, Annette Kluge et al.USENIX Security 2023
