Samenvatting
In this paper we introduce SAIBERSOC, a tool and methodology enabling security researchers and operators to evaluate the performance of deployed and operational Security Operation Centers (SOCs) (or any other security monitoring infrastructure). The methodology relies on the MITRE ATT&CK Framework to define a procedure to generate and automatically inject synthetic attacks in an operational SOC to evaluate any output metric of interest (e.g., detection accuracy, time-to-investigation, etc.). To evaluate the effectiveness of the proposed methodology, we devise an experiment with n = 124 students playing the role of SOC analysts. The experiment relies on a real SOC infrastructure and assigns students to either a BADSOC or a GOODSOC experimental condition. Our results show that the proposed methodology is effective in identifying variations in SOC performance caused by (minimal) changes in SOC configuration. We release the SAIBERSOC tool implementation as free and open source software.
Originele taal-2 | Engels |
---|---|
Titel | Proceedings - 36th Annual Computer Security Applications Conference, ACSAC 2020 |
Plaats van productie | New York, NY, USA |
Uitgeverij | Association for Computing Machinery, Inc |
Pagina's | 141–153 |
Aantal pagina's | 13 |
ISBN van elektronische versie | 9781450388580 |
ISBN van geprinte versie | 9781450388580 |
DOI's | |
Status | Gepubliceerd - 9 dec 2020 |
Evenement | Annual Computer Security Applications Conference 2020 - Duur: 9 dec 2020 → 11 dec 2020 https://www.acsac.org/2020 |
Publicatie series
Naam | ACM International Conference Proceeding Series |
---|
Congres
Congres | Annual Computer Security Applications Conference 2020 |
---|---|
Verkorte titel | ACSAC 2020 |
Periode | 9/12/20 → 11/12/20 |
Internet adres |
Vingerafdruk Duik in de onderzoeksthema's van 'SAIBERSOC: Synthetic Attack Injection to Benchmark and Evaluate the Performance of Security Operation Centers'. Samen vormen ze een unieke vingerafdruk.
Prijzen
-
Distinguished Paper with Artifacts Award
Rosso, Martin (Ontvanger), Campobasso, Michele (Ontvanger), Gankhuyag, Ganduulga (Ontvanger) & Allodi, Luca (Ontvanger), 9 dec 2020
Prijs: Anders › Werk, activiteit of publicatie gerelateerde prijzen (lifetime, best paper, poster etc.) › Wetenschappelijk