• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
搜索

Author:

Liu, Y. (Liu, Y..) | Li, T. (Li, T..) | Zhang, R. (Zhang, R..) | Jin, Z. (Jin, Z..) | Tong, M. (Tong, M..) | Liu, W. (Liu, W..) | Wang, Y. (Wang, Y..) | Yang, Z. (Yang, Z..)

Indexed by:

EI Scopus SCIE

Abstract:

Modern software has evolved from delivering software products to web services and applications, which need to be protected by security operation centers (SOC) against ubiquitous cyber attacks. Numerous security alerts are continuously generated every day, which have to be efficiently and correctly processed to identify potential threats. Many AIOps (artificial intelligence for IT operations) approaches have been proposed to (semi-)automate the inspection of alerts so as to reduce manual effort as much as possible. However, due to the ever-complicating attacks, a significant amount of manual work is still required in practice to ensure correct analysis results. In this paper, we propose a Context-Aware cLustering approach for cLassifying sEcurity alErts (CALLEE), which fully exploits the rich relationships among alerts in order to precisely identify similar alerts, significantly reducing the workload of SOC. Specifically, we first design a core conceptual model to capture connections among security alerts, based on which we establish corresponding heterogeneous information networks. Next, we systematically design a set of meta-paths to profile typical alert scenarios precisely, contributing to obtaining the representation of security alerts. We then cluster security alerts based on their contextual similarities, considering the tradeoff between the number of clusters and the homogeneity of each cluster. Finally, security operators only need to manually inspect a limited number of alerts within each cluster, pragmatically reducing their workload while ensuring the accuracy of alert classification. To evaluate the effectiveness of our approach, we collaborate with our industrial partner and pragmatically apply the approach to a real alert dataset. The results show that our approach can reduce the workload of SOC by 99.76%, outperforming baseline approaches. In addition, we further investigate the integration of our proposal with the real business scenario of our industrial partner. The feedback from practitioners shows that CALLEE is pragmatically applicable and helpful in industrial settings.  © 1976-2012 IEEE.

Keyword:

heterogeneous information network online service systems alert fatigue AIOps

Author Community:

  • [ 1 ] [Liu Y.]Beijing University of Technology, Faculty of Information Technology, Beijing, China
  • [ 2 ] [Li T.]Beijing University of Technology, Faculty of Information Technology, Beijing, China
  • [ 3 ] [Zhang R.]Nsfocus Technologies Group Co., Ltd., Beijing, China
  • [ 4 ] [Jin Z.]Beijing University of Technology, Faculty of Information Technology, Beijing, China
  • [ 5 ] [Tong M.]Nsfocus Technologies Group Co., Ltd., Beijing, China
  • [ 6 ] [Liu W.]Nsfocus Technologies Group Co., Ltd., Beijing, China
  • [ 7 ] [Wang Y.]Beijing University of Technology, Faculty of Information Technology, Beijing, China
  • [ 8 ] [Yang Z.]Beijing University of Technology, Faculty of Information Technology, Beijing, China

Reprint Author's Address:

Email:

Show more details

Related Keywords:

Source :

IEEE Transactions on Software Engineering

ISSN: 0098-5589

Year: 2024

Issue: 1

Volume: 51

Page: 153-171

Cited Count:

WoS CC Cited Count:

SCOPUS Cited Count:

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 2

Affiliated Colleges:

Online/Total:1293/10536669
Address:BJUT Library(100 Pingleyuan,Chaoyang District,Beijing 100124, China Post Code:100124) Contact Us:010-67392185
Copyright:BJUT Library Technical Support:Beijing Aegean Software Co., Ltd.