论文标题

测试使用的工具

Testing SOAR Tools in Use

论文作者

Bridges, Robert A., Rice, Ashley E., Oesch, Sean, Nichols, Jeff A., Watson, Cory, Spakes, Kevin, Norem, Savannah, Huettel, Mike, Jewell, Brian, Weber, Brian, Gannon, Connor, Bizovi, Olivia, Hollifield, Samuel C, Erwin, Samantha

论文摘要

现代安全操作中心(SOCS)依靠运营商以及具有大规模收集和查询能力的登录和警报工具。 SOC调查非常乏味,因为它们依靠手动努力来查询各种数据源,相关的日志,并将数据关联到信息中,然后将其记录在票务系统中。安全编排,自动化和响应(Soar)工具是一项新技术,有望收集,过滤和显示所需的数据;自动化需要SOC分析师时间的常见任务;促进SOC协作;并且,提高SOC的效率和一致性。在实践中,从未对Soar工具进行测试以评估其效果并了解使用中的效果。在本文中,我们设计并管理了第一个动手实践用户研究,涉及24个参与者和6种商业soar工具。我们的贡献包括实验设计,列出了SOAR工具的六个特征以及测试它们的方法。我们描述了网络范围内测试环境的配置,包括网络,用户和威胁仿真;完整的SOC工具套件;并创建工件,允许多个代表性调查方案进行测试。我们介绍了有关Soar工具的第一个研究结果。我们发现SOAR配置至关重要,因为它涉及用于数据显示和自动化的创意设计。我们发现,在调查过程中,Soar工具提高了效率和上下文切换,尽管票务准确性和完整性(表明调查质量)随着SOAR的使用而降低。我们的发现表明,用户偏好与工具的性能略有负相关。高度分析师的关注点是高级分析师的关注点,而平衡的自动化则可以协助用户做出决策。

Modern security operation centers (SOCs) rely on operators and a tapestry of logging and alerting tools with large scale collection and query abilities. SOC investigations are tedious as they rely on manual efforts to query diverse data sources, overlay related logs, and correlate the data into information and then document results in a ticketing system. Security orchestration, automation, and response (SOAR) tools are a new technology that promise to collect, filter, and display needed data; automate common tasks that require SOC analysts' time; facilitate SOC collaboration; and, improve both efficiency and consistency of SOCs. SOAR tools have never been tested in practice to evaluate their effect and understand them in use. In this paper, we design and administer the first hands-on user study of SOAR tools, involving 24 participants and 6 commercial SOAR tools. Our contributions include the experimental design, itemizing six characteristics of SOAR tools and a methodology for testing them. We describe configuration of the test environment in a cyber range, including network, user, and threat emulation; a full SOC tool suite; and creation of artifacts allowing multiple representative investigation scenarios to permit testing. We present the first research results on SOAR tools. We found that SOAR configuration is critical, as it involves creative design for data display and automation. We found that SOAR tools increased efficiency and reduced context switching during investigations, although ticket accuracy and completeness (indicating investigation quality) decreased with SOAR use. Our findings indicated that user preferences are slightly negatively correlated with their performance with the tool; overautomation was a concern of senior analysts, and SOAR tools that balanced automation with assisting a user to make decisions were preferred.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源