Security Operation System
DOI:
https://doi.org/10.34121/1028-9763-2020-2-51-59Keywords:
information security, cyber threat, cyber attack, incident, security event, correlation, analysis, IT infrastructure, SOC, SOS, інформаційна безпека, кіберзагроза, кібератака, інцидент, подія безпеки, кореляція, аналіз, ІТ-інфраструктураAbstract
Abstract. The number of cyber attacks and cyber crimes grows every year. This is why there constantly appear new products, technologies and tools for protection against cyber threats. Security Operation Center (SOC) is one of the most up-to-date and reliable cybersecurity tools of enterprise level. There are already several SOCs in Ukraine in government and law enforcement bodies and there is strong interest to their implementation shown by organizations and enterprises of practically every industry of national economy. SOC allows monitoring, detection and quick response to incidents which is necessary to reduce damage and financial losses caused by such incidents. Implementation of SOC requires significant expenses which can be afforded only by some organizations and enterprises. This is why creation of similar but more affordable tool is very urgent. The paper describes Security Operation System (SOS) designed for effective protection against cyber threats and cyber attacks, which collects, normalizes, correlates and analyses events in organization’s IT infrastructure. Main advantage of this system is ability to receive information on events from different sources and their correlation which is important as today attacks can only be discovered on the basis of combination of events in the IT infrastructure. Another advantage of SOS is ability to add new correlation rules into analytical module which can be based on the unique experience of system exploitation, analysis of new attacks against organization’s IT infrastructure or borrowing such correlation rules from other organizations.References
1. Шейн Х. Кибервойн@. Пятый театр военных действий. Москва: Альпина нон-фикшн, 2016. 392 с.
2. Лисецкий Ю.М., Бобров С.И. Новые угрозы информационной безопасности или оружие массового заражения. Математичні машини і системи. 2018. № 1. С. 41–50.
3. Как быстро запустить свой Security Operation Center (SOC). URL: https://www.anti-malware.ru/analytics/Technology_Analysis/How_fast_run_SOC_Security_Operation_Center.
4. ATT&CK for Enterprise Introduction. URL: https://attack.mitre.org/resources/enterprise-introduction/
5. The Mad Dash to Find a Cybersecurity Force. URL: https://www.nytimes.com/ 2018/11/07/business/the-mad-dash-to-find-a-cybersecurity-force.html.
Published
Issue
Section
License
Copyright (c) 2020 Mathematical Machines and Systems

This work is licensed under a Creative Commons Attribution 4.0 International License.
