Back to Search
Start Over
Humans and Automation: Augmenting Security Operation Centers.
- Source :
- Journal of Cybersecurity & Privacy; Sep2024, Vol. 4 Issue 3, p388-409, 22p
- Publication Year :
- 2024
-
Abstract
- The continuous integration of automated tools into security operation centers (SOCs) increases the volume of alerts for security analysts. This amplifies the risk of automation bias and complacency to the point that security analysts have reported missing, ignoring, and not acting upon critical alerts. Enhancing the SOC environment has predominantly been researched from a technical standpoint, failing to consider the socio-technical elements adequately. However, our research fills this gap and provides practical insights for optimizing processes in SOCs. The synergy between security analysts and automation can potentially augment threat detection and response capabilities, ensuring a more robust defense if effective human-automation collaboration is established. A scoping review of 599 articles from four databases led to a final selection of 49 articles. Thematic analysis resulted in 609 coding references generated across four main themes: SOC automation challenges, automation application areas, implications on analysts, and human factor sentiment. Our findings emphasize the extent to which automation can be implemented across the incident response lifecycle. The SOC Automation Matrix represents our primary contribution to achieving a mutually beneficial relationship between analyst and machine. This matrix describes the properties of four distinct human-automation combinations. This is of practical value to SOCs striving to optimize their processes, as our matrix mentions socio-technical system characteristics for automated tools. [ABSTRACT FROM AUTHOR]
Details
- Language :
- English
- ISSN :
- 2624800X
- Volume :
- 4
- Issue :
- 3
- Database :
- Complementary Index
- Journal :
- Journal of Cybersecurity & Privacy
- Publication Type :
- Academic Journal
- Accession number :
- 180070057
- Full Text :
- https://doi.org/10.3390/jcp4030020