Back to Search Start Over

Humans and Automation: Augmenting Security Operation Centers.

Authors :
Tilbury, Jack
Flowerday, Stephen
Source :
Journal of Cybersecurity & Privacy; Sep2024, Vol. 4 Issue 3, p388-409, 22p
Publication Year :
2024

Abstract

The continuous integration of automated tools into security operation centers (SOCs) increases the volume of alerts for security analysts. This amplifies the risk of automation bias and complacency to the point that security analysts have reported missing, ignoring, and not acting upon critical alerts. Enhancing the SOC environment has predominantly been researched from a technical standpoint, failing to consider the socio-technical elements adequately. However, our research fills this gap and provides practical insights for optimizing processes in SOCs. The synergy between security analysts and automation can potentially augment threat detection and response capabilities, ensuring a more robust defense if effective human-automation collaboration is established. A scoping review of 599 articles from four databases led to a final selection of 49 articles. Thematic analysis resulted in 609 coding references generated across four main themes: SOC automation challenges, automation application areas, implications on analysts, and human factor sentiment. Our findings emphasize the extent to which automation can be implemented across the incident response lifecycle. The SOC Automation Matrix represents our primary contribution to achieving a mutually beneficial relationship between analyst and machine. This matrix describes the properties of four distinct human-automation combinations. This is of practical value to SOCs striving to optimize their processes, as our matrix mentions socio-technical system characteristics for automated tools. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
2624800X
Volume :
4
Issue :
3
Database :
Complementary Index
Journal :
Journal of Cybersecurity & Privacy
Publication Type :
Academic Journal
Accession number :
180070057
Full Text :
https://doi.org/10.3390/jcp4030020