Security Operations Center: A Systematic Study and Open Challenges

Security Operations Center: A Systematic Study and Open Challenges
复制标题

安全运营中心:系统研究和开放挑战

DOI:
10.1109/access.2020.3045514
复制
发表时间:
2020
期刊:
影响因子:
3.9
通讯作者:
G. Pernul
G. Pernul
中科院分区:
计算机科学3区
文献类型:
--
作者:
Manfred Vielberth;Fabian Böhm;Ines Fichtinger;G. Pernul

文献摘要

参考文献

被引文献

相似文献

自从大约15年前引入安全运营中心(SOC)以来,其重要性显著增长,特别是在过去五年中。这主要是由于防止重大网络事件的首要必要性以及由此导致的企业集中安全操作的采用。尽管它们很受欢迎,但现有的关于这一主题的学术工作缺乏普遍接受的观点,主要集中在碎片上,而不是从整体上看待它。这些缺点阻碍了进一步的创新。本文通过文献综述,对不同观点进行了整理。然后使用发现的文献来确定SOC的当前最新技术水平并推导出主要构建块。确定并总结了SOC中的当前挑战。学术研究的一个显著缺点是它关注SOC的人和技术方面,而忽视了这两个领域通过特定过程(特别是非技术过程)的联系。然而,这一领域对于在未来充分发挥SOC的潜力至关重要。
Since the introduction of Security Operations Centers (SOCs) around 15 years ago, their importance has grown significantly, especially over the last five years. This is mainly due to the paramount necessity to prevent major cyber incidents and the resulting adoption of centralized security operations in businesses. Despite their popularity, existing academic work on the topic lacks a generally accepted view and focuses mainly on fragments rather than looking at it holistically. These shortcomings impede further innovation. In this paper, a comprehensive literature survey is conducted to collate different views. The discovered literature is then used to determine the current state-of-the-art of SOCs and derive primary building blocks. Current challenges within a SOC are identified and summarized. A notable shortcoming of academic research is its focus on the human and technological aspects of a SOC while neglecting the connection of these two areas by specific processes (especially by non-technical processes). However, this area is essential for leveraging the full potential of a SOC in the future.
DOI: --
发表时间: 2008-08
期刊: Proceedings from the Sixth Annual IEEE SMC Information Assurance Workshop
影响因子: --
作者:
R. Marty
通讯作者: R. Marty