Machine Learning-Based Enterprise Security Information and Event Management Systems: A Systematic Literature Review
Abstract
-Large firms utilize Security Information and Event Management (SIEM) systems that allow them to gather, normalize, correlate, and analyze security events that, in turn, come from endpoints, networks, identity platforms, cloud services, databases, and applications. Even if traditional rule-based SIEM is indeed useful for regulatory compliance and has an understanding of the attack patterns, it has its limitations due to the existence of high event volume, heterogeneous logs, false positive, alert fatigue, and multi-stage attacks. That's why this article is such a great read! They have done a deep analysis of the various machine learning-based enterprise SIEM systems available. PRISMA 2020 guided the reporting of study selection, while an adapted Waterfall process organized requirements definition, protocol design, search, screening, quality appraisal, extraction, synthesis, and reporting. A careful analysis of thirty studies was conducted with the help of both descriptive and thematic synthesis. The notable findings in the study indicate that the area of research is mostly concerned with log anomaly detection and threat detection. The best techniques for dealing with data that has correct labels & decisions by an analyst are supervised and ensemble methods; on the other hand, the semi-supervised, self-supervised, deep, and transformer-based methods are appropriate for the applications of the large unlabelled log streams; graph-based methods remain as the best option for the events that happen together; and the explainable artificial intelligence is the one that enables trust in analysts. The attention to incidents, system response and defense mechanisms as well as privacy, model drift, adversarial robustness, and the actual security operations center are less supported by involved statistics. It is stated in the article that no one specific machine learning technique is appropriate for each SIEM task. The success of an enterprise deployment is based on implementing the appropriate techniques depending on the security function, data quality, label availability, explanation requirements, and analyst workflow.