Saudi Journal of Engineering and Technology (SJEAT)
Volume-9 | Issue-07 | 334-339
Original Research Article
Alert Prioritization Techniques in Security Monitoring: A Focus on Severity Averaging and Alert Entities
Christian Bassey, Samson Idowu, Courage Ojo
Published : July 24, 2024
Abstract
Security monitoring is a crucial aspect of cybersecurity and a prong of organizational cybersecurity policies. It is achieved primarily using SIEM tools supported by logs ingested from intrusion detection tools and other security solutions. SIEM tools generate alerts of varying severities when detection rules identify anomalies or possible security incidents after analysis of ingested logs. These alerts need to be investigated, but due to the volume of alerts generated and the limited monitoring manhours, it is important to prioritize which security alerts are investigated first. This paper presents a sliding window technique for prioritizing security events by computing a priority value using the severity of previous alerts, alert entities, and criticality ratings. Findings from the experiment show that this approach improves the prioritization of security alerts with severe and medium alerts affecting critical systems prioritized over low, high, and critical alerts affecting non-critical systems. This work can potentially streamline and enhance the efficiency of security monitoring operations.