用图结构聚合安全告警,提升威胁识别效率
A Graph-Based Approach to Alert Contextualisation in Security Operations Centres
- 将告警建模为图节点,时间窗口内关联告警为边
- 通过图聚类捕捉攻击链路,比单个告警更准确
- 适配机器学习模型,辅助分析师快速定位真实威胁
在安全运营中心(SOC)中,处理海量安全告警是一项重大挑战。有效的上下文关联对于快速区分真实威胁与正常行为至关重要,有助于优先处理需深入分析的事件。本文提出一种基于图的方法,将告警聚合为图结构的告警组,其中节点代表告警,边表示在设定时间窗口内的关系。通过将相关告警分组,实现更高层次的分析,更有效地捕捉攻击步骤。此外,为验证该格式适用于下游机器学习方法,我们采用图匹配网络(Graph Matching Networks, GMNs)将新告警组与历史事件进行关联,为分析师提供额外洞察。
原文摘要 · Abstract (English)
Interpreting the massive volume of security alerts is a significant challenge in Security Operations Centres (SOCs). Effective contextualisation is important, enabling quick distinction between genuine threats and benign activity to prioritise what needs further analysis. This paper proposes a graph-based approach to enhance alert contextualisation in a SOC by aggregating alerts into graph-based alert groups, where nodes represent alerts and edges denote relationships within defined time-windows. By grouping related alerts, we enable analysis at a higher abstraction level, capturing attack steps more effectively than individual alerts. Furthermore, to show that our format is well suited for downstream machine learning methods, we employ Graph Matching Networks (GMNs) to correlate incoming alert groups with historical incidents, providing analysts with additional insights.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。