Home / Current Issue / Paper 1723220
Machine Learning-Based Enterprise Security Information and Event Management Systems: A Systematic Literature Review
Subject area: Science,Engineering and Technology · Area of research: Machine Learning
Abstract
Large firms utilize Security Information and Event Management (SIEM) systems that allow them to gather, normalize, correlate, and analyze security events that, in turn, come from endpoints, networks, identity platforms, cloud services, databases, and applications. Even if traditional rule-based SIEM is indeed useful for regulatory compliance and has an understanding of the attack patterns, it has its limitations due to the existence of high event volume, heterogeneous logs, false positive, alert fatigue, and multi-stage attacks. That's why this article is such a great read! They have done a deep analysis of the various machine learning-based enterprise SIEM systems available. PRISMA 2020 guided the reporting of study selection, while an adapted Waterfall process organized requirements definition, protocol design, search, screening, quality appraisal, extraction, synthesis, and reporting. A careful analysis of thirty studies was conducted with the help of both descriptive and thematic synthesis. The notable findings in the study indicate that the area of research is mostly concerned with log anomaly detection and threat detection. The best techniques for dealing with data that has correct labels & decisions by an analyst are supervised and ensemble methods; on the other hand, the semi-supervised, self-supervised, deep, and transformer-based methods are appropriate for the applications of the large unlabelled log streams; graph-based methods remain as the best option for the events that happen together; and the explainable artificial intelligence is the one that enables trust in analysts. The attention to incidents, system response and defense mechanisms as well as privacy, model drift, adversarial robustness, and the actual security operations center are less supported by involved statistics. It is stated in the article that no one specific machine learning technique is appropriate for each SIEM task. The success of an enterprise deployment is based on implementing the appropriate techniques depending on the security function, data quality, label availability, explanation requirements, and analyst workflow.
Keywords
Anomaly detection, Enterprise cybersecurity, Machine learning, Security Information and Event Management, Systematic literature review
References
[1] G. Gonzalez-Granadillo, S. Gonzalez-Zarzosa, and R. Diaz, “Security Information and Event Management (SIEM): Analysis, trends, and usage in critical infrastructures,” Sensors, vol. 21, no. 14, p. 4759, 2021, doi: 10.3390/s21144759. MDPI
[2] K. A. Scarfone and M. P. Souppaya, Cybersecurity Log Management Planning Guide, NIST Special Publication 800-92r1 Initial Public Draft, National Institute of Standards and Technology, 2023, doi: 10.6028/NIST.SP.800-92r1.ipd. NIST
[3] European Union Agency for Cybersecurity, ENISA Threat Landscape 2024, 2024. ENISA
[4] T. Ban, T. Takahashi, S. Ndichu, and D. Inoue, “Breaking alert fatigue: AI-assisted SIEM framework for effective incident response,” Applied Sciences, vol. 13, no. 11, p. 6610, 2023, doi: 10.3390/app13116610. MDPI
[5] N. Tendikov et al., “Security Information Event Management data acquisition and analysis methods with machine learning principles,” Results in Engineering, vol. 22, p. 102254, 2024, doi: 10.1016/j.rineng.2024.102254. ScienceDirect
[6] A. Kapera and M. Niemiec, “Dynamic risk thresholds for SIEM alerting based on machine learning,” IEEE Access, 2025, doi: 10.1109/ACCESS.2025.3588441. IEEE
[7] M. Khayat, E. Barka, M. A. Serhani, and F. Sallabi, “Advanced techniques for alert management in Security Information and Event Management systems with ensembled deep learning, hybrid optimization, and multi-feature extraction,” IEEE Open Journal of the Communications Society, 2025, doi: 10.1109/OJCOMS.2025.3603000. IEEE
[8] H. Sarker, “Machine learning: Algorithms, real-world applications and research directions,” SN Computer Science, vol. 2, p. 160, 2021, doi: 10.1007/s42979-021-00592-x. Springer
[9] X. Zhou, W. Liang, S. Shimizu, J. Ma, and Q. Jin, “Machine learning in cybersecurity: A survey,” ACM Computing Surveys, 2022, doi: 10.1145/3495232.
[10] H. Guo, S. Yuan, and X. Wu, “LogBERT: Log anomaly detection via BERT,” in Proc. International Joint Conference on Neural Networks, 2021, doi: 10.1109/IJCNN52387.2021.9534113. IEEE
[11] M. Landauer, S. Onder, F. Skopik, and M. Wurzenberger, “Deep learning for anomaly detection in log data: A survey,” Machine Learning with Applications, vol. 12, p. 100470, 2023, doi: 10.1016/j.mlwa.2023.100470. ScienceDirect
[12] S. Lu et al., “SSDLog: A semi-supervised dual branch model for log anomaly detection,” World Wide Web, vol. 26, pp. 3137-3153, 2023, doi: 10.1007/s11280-023-01174-y. Springer
[13] M. Li, M. Sun, G. Li, D. Han, and M. Zhou, “MDFULog: Multi-feature deep fusion of unstable log anomaly detection model,” Applied Sciences, vol. 13, no. 4, p. 2237, 2023, doi: 10.3390/app13042237. MDPI
[14] G. Tian, N. Luktarhan, H. Wu, and Z. Shi, “CLDTLog: System log anomaly detection method based on contrastive learning and dual objective tasks,” Sensors, vol. 23, no. 11, p. 5042, 2023, doi: 10.3390/s23115042. MDPI
[15] G. Horvath, A. Meszaros, and P. Szilagyi, “TeleDAL: A regression-based template-less unsupervised method for finding anomalies in log sequences,” The Journal of Supercomputing, vol. 79, pp. 18394-18416, 2023, doi: 10.1007/s11227-023-05379-w. Springer
[16] S. Hashemi and M. Mantyla, “OneLog: Towards end-to-end software log anomaly detection,” Automated Software Engineering, vol. 31, p. 37, 2024, doi: 10.1007/s10515-024-00428-x. Springer
[17] S. Lupton, H. Washizaki, N. Yoshioka, and Y. Fukazawa, “Landscape and taxonomy of online parser-supported log anomaly detection methods,” IEEE Access, 2024, doi: 10.1109/ACCESS.2024.3387287. IEEE
[18] C. Almodovar, F. Sabrina, S. Karimi, and S. A. Azad, “LogFiT: Log anomaly detection using fine-tuned language models,” IEEE Transactions on Network and Service Management, 2024, doi: 10.1109/TNSM.2024.3358730. IEEE
[19] Z. Xu, Z. Wang, J. Xu, H. Shi, and H. Zhao, “Enhancing log anomaly detection with semantic embedding and integrated neural network innovations,” Computers, Materials & Continua, vol. 80, no. 3, pp. 3991-4015, 2024, doi: 10.32604/cmc.2024.051620. Tech Science Press
[20] S. A. Mondal, P. Rv, S. Rao, and A. Menon, “LADDERS: Log based anomaly detection and diagnosis for enterprise systems,” Annals of Data Science, vol. 11, pp. 1165-1183, 2024, doi: 10.1007/s40745-023-00471-7. Springer
[21] H. Maosa, K. Ouazzane, and M. C. Ghanem, “A hierarchical security event correlation model for real-time threat detection and response,” Network, vol. 4, no. 1, pp. 68-90, 2024, doi: 10.3390/network4010004. MDPI
[22] Z. Cheng et al., “KAIROS: Practical intrusion detection and investigation using whole-system provenance,” arXiv:2308.05034, 2023. arXiv
[23] S. Ali, C. Boufaied, D. Bianculli, P. Branco, and L. Briand, “A comprehensive study of machine learning techniques for log-based anomaly detection,” arXiv:2307.16714, 2023. arXiv
[24] Z. A. Khan, D. Shin, D. Bianculli, and L. Briand, “Impact of log parsing on deep learning-based anomaly detection,” arXiv:2305.15897, 2023. arXiv
[25] A. H. Ali et al., “Unveiling machine learning strategies and considerations in intrusion detection systems: A comprehensive survey,” Frontiers in Computer Science, vol. 6, p. 1387354, 2024, doi: 10.3389/fcomp.2024.1387354. Frontiers
[26] Pinto, L. C. Herrera, Y. Donoso, and J. A. Gutierrez, “Survey on intrusion detection systems based on machine learning techniques for the protection of critical infrastructure,” Sensors, vol. 23, no. 5, p. 2415, 2023, doi: 10.3390/s23052415. MDPI
[27] E. Gyamfi and A. Jurcut, “Intrusion detection in Internet of Things systems: A review on design approaches leveraging multi-access edge computing, machine learning, and datasets,” Sensors, vol. 22, no. 10, p. 3744, 2022, doi: 10.3390/s22103744. MDPI
[28] M. Pawlicki, A. Pawlicka, R. Kozik, and M. Choras, “The survey on the dual nature of XAI challenges in intrusion detection and their potential for AI innovation,” Artificial Intelligence Review, vol. 57, p. 330, 2024, doi: 10.1007/s10462-024-10972-3. Springer
[29] O. Arreche, T. R. Guntur, J. W. Roberts, and M. Abdallah, “E-XAI: Evaluating black-box explainable AI frameworks for network intrusion detection,” IEEE Access, 2024, doi: 10.1109/ACCESS.2024.3365140. IEEE
[30] D. Gaspar, P. Silva, and C. Silva, “Explainable AI for intrusion detection systems: LIME and SHAP applicability on multi-layer perceptron,” IEEE Access, 2024, doi: 10.1109/ACCESS.2024.3368377. IEEE
[31] N. H. A. Mutalib et al., “Explainable deep learning approach for advanced persistent threats detection in cybersecurity: A review,” Artificial Intelligence Review, vol. 57, p. 297, 2024, doi: 10.1007/s10462-024-10890-4. Springer
[32] M. Wang, N. Yang, D. H. Gunasinghe, and N. Weng, “On the robustness of ML-based network intrusion detection systems: An adversarial and distribution shift perspective,” Computers, vol. 12, no. 10, p. 209, 2023, doi: 10.3390/computers12100209. MDPI
[33] S. Sharma and Z. Chen, “A systematic study of adversarial attacks against network intrusion detection systems,” Electronics, vol. 13, no. 24, p. 5030, 2024, doi: 10.3390/electronics13245030. MDPI
[34] A. Vassilev, A. Oprea, A. Fordyce, and H. Andersen, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, National Institute of Standards and Technology, 2024, doi: 10.6028/NIST.AI.100-2e2023. NIST
[35] T. D. Le, T. Le-Dinh, and S. Uwizeyemungu, “Cybersecurity analytics for the enterprise environment: A systematic literature review,” Electronics, vol. 14, no. 11, p. 2252, 2025, doi: 10.3390/electronics14112252. MDPI
[36] M. J. Page et al., “The PRISMA 2020 statement: An updated guideline for reporting systematic reviews,” BMJ, vol. 372, p. n71, 2021, doi: 10.1136/bmj.n71. BMJ
[37] Kitchenham and S. Charters, Guidelines for Performing Systematic Literature Reviews in Software Engineering, EBSE Technical Report EBSE-2007-01, Keele University and Durham University, 2007. EBSE
[38] Okoli, “A guide to conducting a standalone systematic literature review,” Communications of the Association for Information Systems, vol. 37, pp. 879-910, 2015, doi: 10.17705/1CAIS.03743. CAIS
[39] H. Snyder, “Literature review as a research methodology: An overview and guidelines,” Journal of Business Research, vol. 104, pp. 333-339, 2019, doi: 10.1016/j.jbusres.2019.07.039. ScienceDirect
[40] W. W. Royce, “Managing the development of large software systems,” in Proc. IEEE WESCON, vol. 26, pp. 1-9, 1970.
How to cite this paper
@article{1723220,
author = {Joshua Ahuose Omoighe, Temitope Atoyebi, Ridwan Kolapo, Prema Kirubakaran},
title = {Machine Learning-Based Enterprise Security Information and Event Management Systems: A Systematic Literature Review},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {3},
pages = {2050-2057},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1723220.pdf},
abstract = {Large firms utilize Security Information and Event Management (SIEM) systems that allow them to gather, normalize, correlate, and analyze security events that, in turn, come from endpoints, networks, identity platforms, cloud services, databases, and applications. Even if traditional rule-based SIEM is indeed useful for regulatory compliance and has an understanding of the attack patterns, it has its limitations due to the existence of high event volume, heterogeneous logs, false positive, alert fatigue, and multi-stage attacks. That's why this article is such a great read! They have done a deep analysis of the various machine learning-based enterprise SIEM systems available. PRISMA 2020 guided the reporting of study selection, while an adapted Waterfall process organized requirements definition, protocol design, search, screening, quality appraisal, extraction, synthesis, and reporting. A careful analysis of thirty studies was conducted with the help of both descriptive and thematic synthesis. The notable findings in the study indicate that the area of research is mostly concerned with log anomaly detection and threat detection. The best techniques for dealing with data that has correct labels & decisions by an analyst are supervised and ensemble methods; on the other hand, the semi-supervised, self-supervised, deep, and transformer-based methods are appropriate for the applications of the large unlabelled log streams; graph-based methods remain as the best option for the events that happen together; and the explainable artificial intelligence is the one that enables trust in analysts. The attention to incidents, system response and defense mechanisms as well as privacy, model drift, adversarial robustness, and the actual security operations center are less supported by involved statistics. It is stated in the article that no one specific machine learning technique is appropriate for each SIEM task. The success of an enterprise deployment is based on implementing the appropriate techniques depending on the security function, data quality, label availability, explanation requirements, and analyst workflow.},
keywords = {Anomaly detection, Enterprise cybersecurity, Machine learning, Security Information and Event Management, Systematic literature review},
month = {September},
}