Enhancing Cyber Resilience: Convergence of SIEM, SOAR, and AI in 2024

Shanmugavelan Ramakrishnan, Dinesh Reddy Chittibala
{"title":"Enhancing Cyber Resilience: Convergence of SIEM, SOAR, and AI in 2024","authors":"Shanmugavelan Ramakrishnan, Dinesh Reddy Chittibala","doi":"10.47941/ijce.1754","DOIUrl":null,"url":null,"abstract":"Purpose: The study aims to examine the synergistic effects of integrating Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), and Artificial Intelligence (AI) technologies in enhancing cybersecurity frameworks. It explores how this combination can lead to a transformative era in cybersecurity, focusing on the improved efficacy of threat management and incident response. \nMethodology: An analytical approach was used to investigate the integration trends between SIEM and SOAR technologies, underpinned by advancements in AI. This method emphasizes accelerated incident detection and response, enriched threat intelligence collaboration, and fortified security strategies. \nFindings: The fusion of SIEM, SOAR, and AI technologies has led to a paradigm shift in cybersecurity, offering unparalleled efficiency in threat management and a significant reduction in the impacts of cyber incidents on entities. It highlights the accelerated detection and response to incidents and the enhancement of threat intelligence collaboration and security strategies. \nUnique Contribution to Theory, Practice, and Policy: This study contributes to the field by presenting invaluable insights for cybersecurity practitioners and entities aiming to strengthen their defenses against an evolving digital threat landscape. It advocates for a proactive orchestration of security measures, underlining the strategic implications of the SIEM-SOAR-AI triad for future cybersecurity endeavors. Recommendations are provided for entities to adopt this integrated approach to enhance their cybersecurity frameworks effectively.","PeriodicalId":503134,"journal":{"name":"International Journal of Computing and Engineering","volume":"93 12","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2024-03-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Computing and Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.47941/ijce.1754","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Purpose: The study aims to examine the synergistic effects of integrating Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), and Artificial Intelligence (AI) technologies in enhancing cybersecurity frameworks. It explores how this combination can lead to a transformative era in cybersecurity, focusing on the improved efficacy of threat management and incident response. Methodology: An analytical approach was used to investigate the integration trends between SIEM and SOAR technologies, underpinned by advancements in AI. This method emphasizes accelerated incident detection and response, enriched threat intelligence collaboration, and fortified security strategies. Findings: The fusion of SIEM, SOAR, and AI technologies has led to a paradigm shift in cybersecurity, offering unparalleled efficiency in threat management and a significant reduction in the impacts of cyber incidents on entities. It highlights the accelerated detection and response to incidents and the enhancement of threat intelligence collaboration and security strategies. Unique Contribution to Theory, Practice, and Policy: This study contributes to the field by presenting invaluable insights for cybersecurity practitioners and entities aiming to strengthen their defenses against an evolving digital threat landscape. It advocates for a proactive orchestration of security measures, underlining the strategic implications of the SIEM-SOAR-AI triad for future cybersecurity endeavors. Recommendations are provided for entities to adopt this integrated approach to enhance their cybersecurity frameworks effectively.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
增强网络复原力:2024 年 SIEM、SOAR 和 AI 的融合
目的:本研究旨在探讨将安全信息和事件管理(SIEM)、安全协调、自动化和响应(SOAR)以及人工智能(AI)技术整合到增强网络安全框架中的协同效应。它探讨了这种结合如何能带来网络安全的变革时代,重点是提高威胁管理和事件响应的效率。研究方法:采用分析方法来研究 SIEM 和 SOAR 技术之间的整合趋势,并以人工智能的进步为基础。这种方法强调加速事件检测和响应、丰富威胁情报协作以及强化安全策略。研究结果:SIEM、SOAR 和人工智能技术的融合带来了网络安全模式的转变,提供了无与伦比的威胁管理效率,并显著降低了网络事件对实体的影响。它突出强调了对事件的加速检测和响应,以及威胁情报协作和安全战略的加强。对理论、实践和政策的独特贡献:本研究为网络安全从业人员和旨在加强防御以应对不断变化的数字威胁环境的实体提供了宝贵的见解,从而为该领域做出了贡献。它倡导主动协调安全措施,强调了 SIEM-SOAR-AI 三合一对未来网络安全工作的战略意义。报告建议各实体采用这种综合方法来有效加强其网络安全框架。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Enhancing Cyber Resilience: Convergence of SIEM, SOAR, and AI in 2024 Cloud Cost Optimization: Achieving Cost Savings through AWS Spot Fleet Utilization and Optimizing Cloud Resource Usage Advancements in Automated Code Scanning Techniques for Detecting Security Vulnerabilities in Open Source Software Unveiling the AWS SAM Magic for Serverless Restful APIs: Architecting with ALB Path-Based Routing in AWS Artificial Intelligence and Energy Efficiency of 5G Radio Access Network
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1