Home / Current Issue / Paper 1706589
A Mini SIEM/SOAR System for Comprehensive Cybersecurity Monitoring of Microsoft Azure
Subject area: Science,Engineering and Technology · Area of research: Cybersecurity
Abstract
Outsourcing security management has gained traction among numerous organizations, often serving as the sole viable option in the absence of internal proficiency and infrastructure. The implementation of modern systems alone is no longer adequate for robust cybersecurity threat management. Managed security service providers now offer a comprehensive set of mature security monitoring and management capabilities, including security information and event management, strategic oversight of organizational governance, enterprise risk, and compliance with regulatory standards, making them a favored choice for a multitude of organizations. In an era of escalating cyber threats and data flood, the critical role of Security Operations Centers (SOCs) in safeguarding organizations' digital assets cannot be overstated. This work investigates how cybersecurity capabilities can be improved by creating and deploying a scaled-down version of Security Orchestration, Automation, and Response (SOAR) within Security Information and Event Management (SIEM) systems in Microsoft Azure environments. This setup would enable monitoring of various aspects including Network Security Group "firewall," endpoints, networks, and cloud resources. Acknowledging the mounting challenges faced by traditional security operation centers (SOC), they are overwhelmed with the ever-increasing volumes of data/alerts, while cyberattacks grow more sophisticated, often eluding conventional detection methods.
Keywords
SOC, SIEM, SOAR, Logic App, Incident Response, Azure
References
[1] Wikipedia, "Microsoft Azure," [Online]. Available: https://en.wikipedia.org/wiki/Microsoft_Azure
[2] VentureBeat, "Cyberattack response time averages 2 days," October 13, 2021, https://venturebeat.com/business/cyberattack-response-time-averages-2-days-report-finds/
[3] Critical Start, "THE IMPACT OF SECURITY ALERT OVERLOAD", https://www.criticalstart.com/wp-content/uploads/2021/02/CS_Report-The-Impact-of-Security-Alert-Overload.pdf
[4] Gartner, Inc, "Innovation Insight for Security Orchestration, Automation and Response," 2017, https://www.gartner.com/en/documents/3834578
[5] Microsoft, "What is Microsoft Sentinel?", https://learn.microsoft.com/en-us/azure/sentinel/overview?tabs=azure-portal
[6] C. Davis, Cloud-Native Patterns: Designing Change-Tolerant Software, Manning Publications, 2019.
[7] H. R. Wiem Tounsi, A survey on technical threat intelligence in the age of sophisticated cyber-attacks, Elsevier, 2018.
[8] IBM, "What is SOAR?", IBM, 2021 https://mediacenter.ibm.com/media/What%20is%20SOAR%20(Security%2C%20Orchestration%2C%20Automation%20and%20Response)/1_lsc3n40h
[9] I. M. a. A. B. A. Serckumecka, "Low-Cost Serverless SIEM in the Cloud: 2019 38th Symposium on Reliable Distributed Systems (SRDS)," Lyon, France, 2019.
[10] J. N. D. Huang, "Trust mechanisms for cloud computing," Journal of Cloud Computing: Advances, Systems and Applications, 2013.
How to cite this paper
@article{1706589,
author = {Taofeek Olayinka Agboola, Pushkar Ogale},
title = {A Mini SIEM/SOAR System for Comprehensive Cybersecurity Monitoring of Microsoft Azure},
journal = {Iconic Research And Engineering Journals},
year = {2024},
volume = {8},
number = {5},
pages = {1232-1239},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1706589.pdf},
abstract = {Outsourcing security management has gained traction among numerous organizations, often serving as the sole viable option in the absence of internal proficiency and infrastructure. The implementation of modern systems alone is no longer adequate for robust cybersecurity threat management. Managed security service providers now offer a comprehensive set of mature security monitoring and management capabilities, including security information and event management, strategic oversight of organizational governance, enterprise risk, and compliance with regulatory standards, making them a favored choice for a multitude of organizations. In an era of escalating cyber threats and data flood, the critical role of Security Operations Centers (SOCs) in safeguarding organizations' digital assets cannot be overstated. This work investigates how cybersecurity capabilities can be improved by creating and deploying a scaled-down version of Security Orchestration, Automation, and Response (SOAR) within Security Information and Event Management (SIEM) systems in Microsoft Azure environments. This setup would enable monitoring of various aspects including Network Security Group "firewall," endpoints, networks, and cloud resources. Acknowledging the mounting challenges faced by traditional security operation centers (SOC), they are overwhelmed with the ever-increasing volumes of data/alerts, while cyberattacks grow more sophisticated, often eluding conventional detection methods.},
keywords = {SOC, SIEM, SOAR, Logic App, Incident Response, Azure},
month = {November},
}