About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
sesa 19(18): e1

Research Article

Monitoring and Improving Managed Security Services inside a Security Operation Center

Download1819 downloads
Cite
BibTeX Plain Text
  • @ARTICLE{10.4108/eai.8-4-2019.157413,
        author={Mina Khalili and Mengyuan Zhang and Daniel Borbor and Lingyu Wang and Nicandro Scarabeo and Michel-Ange Zamor},
        title={Monitoring and Improving Managed Security Services inside a Security Operation Center},
        journal={EAI Endorsed Transactions on Security and Safety},
        volume={5},
        number={18},
        publisher={EAI},
        journal_a={SESA},
        year={2019},
        month={1},
        keywords={Managed Security Services, Network Security Monitoring, Security Operation Center, Performance Metrics, Service Level Agreement, SLA, SOC, MSS, NSM, Security analysts},
        doi={10.4108/eai.8-4-2019.157413}
    }
    
  • Mina Khalili
    Mengyuan Zhang
    Daniel Borbor
    Lingyu Wang
    Nicandro Scarabeo
    Michel-Ange Zamor
    Year: 2019
    Monitoring and Improving Managed Security Services inside a Security Operation Center
    SESA
    EAI
    DOI: 10.4108/eai.8-4-2019.157413
Mina Khalili1, Mengyuan Zhang1,*, Daniel Borbor1, Lingyu Wang1, Nicandro Scarabeo2, Michel-Ange Zamor3
  • 1: Concordia Institute for Information Systems Engineering (CIISE), Concordia University, Montreal, QC H3G 1M8, Canada
  • 2: University of Cassino and Southern Lazio, Viale dell’Università, 03043 Cassino FR, Italy
  • 3: Département d’informatique, Université de Sherbrooke, Sherbrooke, QC J1K 2R1, Canada
*Contact email: mengy_zh@ciise.concordia.ca

Abstract

Monitoring and improving the performance of Security Operation Centers (SOC) are becoming crucial due to the emerging need of benefiting from Managed Security Services (MSS) rather than hiring in-house security experts. In this paper, by observing workflows of a real-world SOC, a system consisting of three different modules is designed for monitoring analysts’ activities, analysis performance measurement, and performing simulation scenarios. The system empowers managers to evaluate the SOC’s performance, which helps them to conform to Service Level Agreement (SLA) and see the need for improvement. Moreover, the designed system is strengthened by a background service module to provide feedback about anomalies or informative issues for security analysts. Three case studies have been conducted based on real data collected from the operational SOC, and simulation results have demonstrated the effectiveness of the different modules of the designed system in improving the SOC performance.

Keywords
Managed Security Services, Network Security Monitoring, Security Operation Center, Performance Metrics, Service Level Agreement, SLA, SOC, MSS, NSM, Security analysts
Received
2018-11-28
Accepted
2018-12-19
Published
2019-01-25
Publisher
EAI
http://dx.doi.org/10.4108/eai.8-4-2019.157413

Copyright © 2019 Mina Khalili et al., licensed to EAI. This is an open access article distributed under the terms of the Creative Commons Attribution license (http://creativecommons.org/licenses/by/3.0/), which permits unlimited use, distribution and reproduction in any medium so long as the original work is properly cited.

EBSCOProQuestDBLPDOAJPortico
EAI Logo

About EAI

  • Who We Are
  • Leadership
  • Research Areas
  • Partners
  • Media Center

Community

  • Membership
  • Conference
  • Recognition
  • Sponsor Us

Publish with EAI

  • Publishing
  • Journals
  • Proceedings
  • Books
  • EUDL