paper-with-me

홈 › Papers

A Graph-Based Approach to Alert Contextualisation in Security Operations Centres

2025-09-16 · Magnus Wiik Eckhoff, Peter Marius Flydal, Siem Peters, Martin Eian, Jonas Halvorsen, Vasileios Mavroeidis, Gudmund Grov arxiv

Interpreting the massive volume of security alerts is a significant challenge in Security Operations Centres (SOCs). Effective contextualisation is important, enabling quick distinction between genuine threats and benign activity to prioritise what needs further analysis. This paper proposes a graph-based approach to enhance alert contextualisation in a SOC by aggregating alerts into graph-based alert groups, where nodes represent alerts and edges denote relationships within defined time-windows. By grouping related alerts, we enable analysis at a higher abstraction level, capturing attack steps more effectively than individual alerts. Furthermore, to show that our format is well suited for downstream machine learning methods, we employ Graph Matching Networks (GMNs) to correlate incoming alert groups with historical incidents, providing analysts with additional insights.

📄 PDF Abstract BibTeX arXiv:2509.12923

Code (0)

등록된 구현이 없습니다.

Tasks

Graph Matching

Similar Papers 제목 키워드 기반

AlertBERT: A noise-robust alert grouping framework for simultaneous cyber attacks

2026-02-06 · Lukas Karner, Max Landauer, Markus Wurzenberger, Florian Skopik arxiv

Automated detection of cyber attacks is a critical capability to counteract the growing volume and sophistication of cyber attacks. However, the high numbers of security alerts issued by intrusion detection systems lead …

Intrusion DetectionData AugmentationDecision Making

Generative AI in Live Operations: Evidence of Productivity Gains in Cybersecurity and Endpoint Management

2025-04-09 · James Bono, Justin Grana, Kleanthis Karakolios, Pruthvi Hanumanthapura Ramakrishna 외

We measure the association between generative AI (GAI) tool adoption and four metrics spanning security operations, information protection, and endpoint management: 1) number of security alerts per incident, 2) probabili…

Causal IdentificationManagement

Automated Alert Classification and Triage (AACT): An Intelligent System for the Prioritisation of Cybersecurity Alerts

2025-05-14 · Melissa Turcotte, François Labrèche, Serge-Olivier Paquette

Enterprise networks are growing ever larger with a rapidly expanding attack surface, increasing the volume of security alerts generated from security controls. Security Operations Centre (SOC) analysts triage these alert…

CyberAId: AI-Driven Cybersecurity for Financial Service Providers

2026-05-03 · George Fatouros, Georgios Makridis, John Soldatos, Dimosthenis Kyriazis 외 arxiv

European financial institutions face mounting regulatory pressure while their security operations centres remain constrained not by data or staffing but by reasoning capacity: enterprise SIEMs cover only a fraction of MI…

Intrusion Detection

Survey Perspective: The Role of Explainable AI in Threat Intelligence

2025-03-03 · Nidhi Rastogi, Devang Dhanuka, Amulya Saxena, Pranjal Mairal 외

The increasing reliance on AI-based security tools in Security Operations Centers (SOCs) has transformed threat detection and response, yet analysts frequently struggle with alert overload, false positives, and lack of c…

Decision MakingNavigateSurvey