Design and Generation of a Set of Declarative APIs for Security Orchestration
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216208%3A11320%2F25%3AMJWI7AXW" target="_blank" >RIV/00216208:11320/25:MJWI7AXW - isvavai.cz</a>
Nalezeny alternativní kódy
RIV/00216208:11320/23:FCFCBWMP
Výsledek na webu
<a href="https://www.scopus.com/inward/record.uri?eid=2-s2.0-85179115313&doi=10.1109%2fTSC.2023.3336666&partnerID=40&md5=04abb6d69632ab409bad1165fd770027" target="_blank" >https://www.scopus.com/inward/record.uri?eid=2-s2.0-85179115313&doi=10.1109%2fTSC.2023.3336666&partnerID=40&md5=04abb6d69632ab409bad1165fd770027</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1109/TSC.2023.3336666" target="_blank" >10.1109/TSC.2023.3336666</a>
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
Design and Generation of a Set of Declarative APIs for Security Orchestration
Popis výsledku v původním jazyce
The emerging threat landscape causes continuous change in the Incident Response Process (IRP) and security tools of security orchestration platforms (SOAR). Users of such platforms often struggle to adapt to these changes because they are addressed in an ad-hoc manner through a complex architecture. The complex design of the SOAR can be hidden behind an easy-to-use user interface. This article introduces a Declarative API (DAPI)-driven Orchestration approach, DecOr, that alleviates the need for security teams' detailed understanding of the libraries and plugins to address the changes of a SOAR. DecOr comprises 1) three sets of dAPIs to encapsulate the activities of security orchestration and 2) a semantic framework to support the design and generation of dAPIs from task descriptions, leveraging natural language processing techniques. The dAPIs are mapped with an ontological knowledge base to execute IRPs. We experimentally evaluate the effectiveness and efficiency of DecOr based on 147 task and dAPI pairs, curated from real-world playbooks. We show the end-to-end process from identifying dAPIs to executing 48 IRPs with seven security tools. The evaluation results show, DecOr accurately generates dAPIs in near real-time, with precision and recall values over 80% and successfully executes changing IRPs 93% of the time. © 2008-2012 IEEE.
Název v anglickém jazyce
Design and Generation of a Set of Declarative APIs for Security Orchestration
Popis výsledku anglicky
The emerging threat landscape causes continuous change in the Incident Response Process (IRP) and security tools of security orchestration platforms (SOAR). Users of such platforms often struggle to adapt to these changes because they are addressed in an ad-hoc manner through a complex architecture. The complex design of the SOAR can be hidden behind an easy-to-use user interface. This article introduces a Declarative API (DAPI)-driven Orchestration approach, DecOr, that alleviates the need for security teams' detailed understanding of the libraries and plugins to address the changes of a SOAR. DecOr comprises 1) three sets of dAPIs to encapsulate the activities of security orchestration and 2) a semantic framework to support the design and generation of dAPIs from task descriptions, leveraging natural language processing techniques. The dAPIs are mapped with an ontological knowledge base to execute IRPs. We experimentally evaluate the effectiveness and efficiency of DecOr based on 147 task and dAPI pairs, curated from real-world playbooks. We show the end-to-end process from identifying dAPIs to executing 48 IRPs with seven security tools. The evaluation results show, DecOr accurately generates dAPIs in near real-time, with precision and recall values over 80% and successfully executes changing IRPs 93% of the time. © 2008-2012 IEEE.
Klasifikace
Druh
J<sub>SC</sub> - Článek v periodiku v databázi SCOPUS
CEP obor
—
OECD FORD obor
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Návaznosti výsledku
Projekt
—
Návaznosti
—
Ostatní
Rok uplatnění
2024
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Název periodika
IEEE Transactions on Services Computing
ISSN
1939-1374
e-ISSN
—
Svazek periodika
17
Číslo periodika v rámci svazku
1
Stát vydavatele periodika
US - Spojené státy americké
Počet stran výsledku
15
Strana od-do
127-141
Kód UT WoS článku
—
EID výsledku v databázi Scopus
2-s2.0-85179115313