arXiv:2505.09843cs.CRcs.LG2025-05被引 16

自动分类安全告警,减轻分析师负担。

Automated Alert Classification and Triage (AACT): An Intelligent System for the Prioritisation of Cybersecurity Alerts

  • 基于分析师处理行为学习,实时预测告警优先级。
  • 在真实环境中减少61%告警,误漏率仅1.36%。
  • 适合需要提升SOC效率的网络安全团队。

企业网络规模持续扩大,攻击面不断延伸,导致安全设备生成大量告警。安全运营中心(SOC)分析师需对这些告警进行研判,但因海量良性告警导致告警疲劳。机构转向托管SOC服务,却面临上下文切换频繁、业务流程可见性差的问题。本文提出新型系统AACT,通过学习分析师对安全告警的处置行为,自动化完成告警分类与优先级排序。系统可实时预测告警处置结果,自动关闭良性告警,突出显示关键威胁,显著降低告警队列压力,使分析师聚焦于高危、相关或模糊的事件。该系统在真实SOC数据及公开数据集上训练评估,表现优异。在实际部署中,六个月内将呈现给分析师的告警减少61%,在数百万告警中保持1.36%的低误漏率。

原文摘要 · Abstract (English)

Enterprise networks are growing ever larger with a rapidly expanding attack surface, increasing the volume of security alerts generated from security controls. Security Operations Centre (SOC) analysts triage these alerts to identify malicious activity, but they struggle with alert fatigue due to the overwhelming number of benign alerts. Organisations are turning to managed SOC providers, where the problem is amplified by context switching and limited visibility into business processes. A novel system, named AACT, is introduced that automates SOC workflows by learning from analysts' triage actions on cybersecurity alerts. It accurately predicts triage decisions in real time, allowing benign alerts to be closed automatically and critical ones prioritised. This reduces the SOC queue allowing analysts to focus on the most severe, relevant or ambiguous threats. The system has been trained and evaluated on both real SOC data and an open dataset, obtaining high performance in identifying malicious alerts from benign alerts. Additionally, the system has demonstrated high accuracy in a real SOC environment, reducing alerts shown to analysts by 61% over six months, with a low false negative rate of 1.36% over millions of alerts.

安全告警智能分析SOC自动化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。