<p>Security Operations Centres (SOCs) face alert fatigue and undetected threats in cloud-native environments, as traditional SIEM systems struggle to analyze high-volume logs from containerized microservices. These threats often remain hidden during routine monitoring, only surfacing during prolonged investigations, which delays mitigation and increases operational risks. Semantic technologies have shown promise for transforming heterogeneous data into contextualized insights; however, traditional approaches falter when aggregating heterogeneous sources. This work tackles this gap by proposing a hybrid knowledge graph (KG) combining rule-based detection with KG-assisted investigation, leveraging kernel-level telemetry and the Elastic Common Schema (ECS). Our experimental validation, conducted within the investigation phase of a cloud-native SOC, demonstrates a 20<InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10586_2025_5531_Article_IEq1.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="15" /> </InlineMediaObject> <EquationSource Format="TEX">\(\%\)</EquationSource> </InlineEquation> reduction in time latency for contextualized threat analysis compared to traditional SIEM workflows, while enabling complex cross-layer queries that uncover relationships previously unattainable with rule-based methods.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Enhancing cloud native security: a knowledge graph approach for securing container runtimes

  • Amina Eldjou,
  • Ilham Kitouni,
  • Zakaria Benmounah,
  • Samir Bennacer

摘要

Security Operations Centres (SOCs) face alert fatigue and undetected threats in cloud-native environments, as traditional SIEM systems struggle to analyze high-volume logs from containerized microservices. These threats often remain hidden during routine monitoring, only surfacing during prolonged investigations, which delays mitigation and increases operational risks. Semantic technologies have shown promise for transforming heterogeneous data into contextualized insights; however, traditional approaches falter when aggregating heterogeneous sources. This work tackles this gap by proposing a hybrid knowledge graph (KG) combining rule-based detection with KG-assisted investigation, leveraging kernel-level telemetry and the Elastic Common Schema (ECS). Our experimental validation, conducted within the investigation phase of a cloud-native SOC, demonstrates a 20 \(\%\) reduction in time latency for contextualized threat analysis compared to traditional SIEM workflows, while enabling complex cross-layer queries that uncover relationships previously unattainable with rule-based methods.