The increasing number and sophistication of cybersecurity threats nowadays demand constant vigilance and rapid response capabilities as the stakes for protecting digital assets are higher than ever. As a result, we have a widespread adoption of SOCs (Security Operations Centers) by companies across different sectors to afford an effective, highly focused resource for detecting and responding actively to cybersecurity incidents. The purpose is to clearly define the SOC′s objectives and scope and choose the right technologies, cybersecurity professional, and SOC analysts while developing and documenting processes for the SOC lifecycle. Choosing the right technologies and ensuring they integrate well with companies’ existing IT infrastructure and device products and vendors list is particularly important for the SOC scope coverage definition when defining the SOC security monitoring of the use cases definition. This study aims at analysing the SOC technical coverage and using the application of the MITRE ATT&CK framework for tactics and techniques to check for loopholes in detection rules with respect to the organization′s existent security technologies.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

SOC Use Cases: Deployment, Challenges and Gap Assessment Based on MITRE ATT&CK

  • Samir Achraf Chamkar,
  • Yassine Maleh,
  • Noreddine Gherabi

摘要

The increasing number and sophistication of cybersecurity threats nowadays demand constant vigilance and rapid response capabilities as the stakes for protecting digital assets are higher than ever. As a result, we have a widespread adoption of SOCs (Security Operations Centers) by companies across different sectors to afford an effective, highly focused resource for detecting and responding actively to cybersecurity incidents. The purpose is to clearly define the SOC′s objectives and scope and choose the right technologies, cybersecurity professional, and SOC analysts while developing and documenting processes for the SOC lifecycle. Choosing the right technologies and ensuring they integrate well with companies’ existing IT infrastructure and device products and vendors list is particularly important for the SOC scope coverage definition when defining the SOC security monitoring of the use cases definition. This study aims at analysing the SOC technical coverage and using the application of the MITRE ATT&CK framework for tactics and techniques to check for loopholes in detection rules with respect to the organization′s existent security technologies.