International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1706589

1706589 Vol 8 · Issue 5 Download Paper

A Mini SIEM/SOAR System for Comprehensive Cybersecurity Monitoring of Microsoft Azure

Taofeek Olayinka Agboola Pushkar Ogale

Subject area: Science,Engineering and Technology  ·  Area of research: Cybersecurity

Abstract

Outsourcing security management has gained traction among numerous organizations, often serving as the sole viable option in the absence of internal proficiency and infrastructure. The implementation of modern systems alone is no longer adequate for robust cybersecurity threat management. Managed security service providers now offer a comprehensive set of mature security monitoring and management capabilities, including security information and event management, strategic oversight of organizational governance, enterprise risk, and compliance with regulatory standards, making them a favored choice for a multitude of organizations. In an era of escalating cyber threats and data flood, the critical role of Security Operations Centers (SOCs) in safeguarding organizations' digital assets cannot be overstated. This work investigates how cybersecurity capabilities can be improved by creating and deploying a scaled-down version of Security Orchestration, Automation, and Response (SOAR) within Security Information and Event Management (SIEM) systems in Microsoft Azure environments. This setup would enable monitoring of various aspects including Network Security Group "firewall," endpoints, networks, and cloud resources. Acknowledging the mounting challenges faced by traditional security operation centers (SOC), they are overwhelmed with the ever-increasing volumes of data/alerts, while cyberattacks grow more sophisticated, often eluding conventional detection methods.

Keywords

SOC, SIEM, SOAR, Logic App, Incident Response, Azure

How to cite this paper

Taofeek Olayinka Agboola, Pushkar Ogale "A Mini SIEM/SOAR System for Comprehensive Cybersecurity Monitoring of Microsoft Azure" Iconic Research And Engineering Journals, vol. 8, no. 5, Nov. 2024
Taofeek Olayinka Agboola, Pushkar Ogale (2024). A Mini SIEM/SOAR System for Comprehensive Cybersecurity Monitoring of Microsoft Azure. Iconic Research And Engineering Journals, 8(5).
Taofeek Olayinka Agboola, Pushkar Ogale "A Mini SIEM/SOAR System for Comprehensive Cybersecurity Monitoring of Microsoft Azure" Iconic Research And Engineering Journals, vol. 8, no. 5, Nov. 2024.
@article{1706589,
      author = {Taofeek Olayinka Agboola, Pushkar Ogale},
      title = {A Mini SIEM/SOAR System for Comprehensive Cybersecurity Monitoring of Microsoft Azure},
      journal = {Iconic Research And Engineering Journals},
      year = {2024},
      volume = {8},
      number = {5},
      pages = {1232-1239},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1706589.pdf},
      abstract = {Outsourcing security management has gained traction among numerous organizations, often serving as the sole viable option in the absence of internal proficiency and infrastructure. The implementation of modern systems alone is no longer adequate for robust cybersecurity threat management. Managed security service providers now offer a comprehensive set of mature security monitoring and management capabilities, including security information and event management, strategic oversight of organizational governance, enterprise risk, and compliance with regulatory standards, making them a favored choice for a multitude of organizations. In an era of escalating cyber threats and data flood, the critical role of Security Operations Centers (SOCs) in safeguarding organizations' digital assets cannot be overstated. This work investigates how cybersecurity capabilities can be improved by creating and deploying a scaled-down version of Security Orchestration, Automation, and Response (SOAR) within Security Information and Event Management (SIEM) systems in Microsoft Azure environments. This setup would enable monitoring of various aspects including Network Security Group "firewall," endpoints, networks, and cloud resources. Acknowledging the mounting challenges faced by traditional security operation centers (SOC), they are overwhelmed with the ever-increasing volumes of data/alerts, while cyberattacks grow more sophisticated, often eluding conventional detection methods.},
      keywords = {SOC, SIEM, SOAR, Logic App, Incident Response, Azure},
      month = {November},
  }