Affiliation:
1. Eindhoven University of Technology, Eindhoven, The Netherlands
Abstract
In this article, we introduce
SAIBERSOC
(Synthetic Attack Injection to Benchmark and Evaluate the Performance of Security Operation Centers), a tool and methodology enabling security researchers and operators to evaluate the performance of deployed and operational Security Operation Centers (SOC)—or any other security monitoring infrastructure. The methodology relies on the MITRE ATT&CK Framework to define a procedure to generate and automatically inject synthetic attacks in an operational SOC to evaluate any output metric of interest (e.g., detection accuracy, time-to-investigation). To evaluate the effectiveness of the proposed methodology, we devise an experiment with
n=124
students playing the role of SOC analysts. The experiment relies on a real SOC infrastructure and assigns students to either a
BADSOC
or a
GOODSOC
experimental condition. Our results show that the proposed methodology is effective in identifying variations in SOC performance caused by (minimal) changes in SOC configuration. We release the
SAIBERSOC
tool implementation as free and open source software.
Funder
ITEA3 program by Rijksdienst voor Ondernemend Nederland
Nederlandse Organisatie voor Wetenschappelijk Onderzoek
Publisher
Association for Computing Machinery (ACM)
Cited by
2 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献