Skip to content
Review Open access

An Overview of EDR Serviceability for Security Information and Event Management (SIEM)

Jul 2026 · Journal of Information Assurance and Security · Vol 21, pp. 52 - 88 · 0 citations · 122 references

TL;DR

This review synthesizes key developments and innovations in the EDR-SIEM domain, drawing from academic research, industry analysis, and real-world applications to contribute to higher quality, improved performance, effective cost management, better decision-making, and reduced risk.

Abstract

Abstract This review paper focuses on and addresses Endpoint Detection and Response (EDR) tools, providing an overview of their purpose, functions, operations, services, and benefits within the cybersecurity landscape. Specifically, EDR solutions are designed to detect, prevent, investigate, and respond to advanced cyber threats that often bypass traditional antivirus programs. To achieve this, these tools continuously collect and analyze data in real time using behavioral analytics, artificial intelligence (AI), and machine learning (ML). This enables the identification of anomalous activities and sophisticated attack patterns, such as zero-day exploits and fileless malware. Furthermore, the integration of open-source tools strengthens an organization's security posture by enhancing service capabilities, scalability, reliability, and availability. The paper also discusses the evolution of EDR from standalone tools to integrated, interoperable, automated, and intelligence-driven platforms that utilize behavioral and predictive analysis to counter increasingly sophisticated threats. Such integration, in turn, enables faster decision-making while reducing code complexity, operational costs, and response times. Ultimately, the sustainability of open-source tools contributes to higher quality, improved performance, effective cost management, better decision-making, and reduced risk. In summary, this review synthesizes key developments and innovations in the EDR-SIEM domain, drawing from academic research, industry analysis, and real-world applications.

Read PDF

Similar papers

Open access Jul 2026

SOAR Automation Platform for Cybersecurity Incident Response

Increasing numbers of cyberattacks led to increasing workload for Security Operations Centers (SOCs). SOC analysts are inundated with hundreds and thousands of alerts from SIEM, IDS/IPS, EDR, firewalls, and cloud/endpoint security systems. Manual investigation leads to alert fatigue, slow responses, and inconsistencies. This paper will focus on an AI-driven Security Orchestration, Automation and Response (SOAR) platform that involves: secure authentication, central monitoring, machine learning-based anomaly detection, Groq AI-driven incident analysis, threat intelligence enhancement, n8n workflow automation, AI chatbot, and automatic reporting. The unified platform increases efficiency, drastically reduce human effort to repetitive work, quick incident response times, enhances the quality of investigations, and provides a comprehensive view of an organizations security posture. The platform is also modular to further integrate with cloud security, SIEM, EDR, malware analysis and predictive analyses

Bhumika A R, Jhanavi H N, Prof. Thejaswini M N · 0 citations
Open access Jul 2026

Modern cybersecurity architecture for fraud prevention in administrative services

As service organizations advance in their digital modernization, security does not always keep pace, generating vulnerabilities that conventional protection schemes fail to address. To tackle this problem, the present work proposes a cybersecurity architecture oriented toward fraud prevention in a service sector company in Lima, Peru, whose design is grounded in the documentary analysis of 385 technical incident records. This analysis revealed that only 54.3% of vulnerabilities were addressed annually, with monthly fluctuations between 44.4% and 62.5%, while the effective response rate did not exceed 34%, reaching lows of 19% during periods of peak operational load. These findings, combined with the concentration of unresolved incidents in malware, unknown threats, and ransomware, expose structural failures in the prioritization and closure of security events. In response to this diagnosis, the proposed architecture integrates identity and access management, advanced threat protection, cloud security, regulatory compliance, and extended analytics powered by artificial intelligence, forming a defense-in-depth capable of reducing residual exposure and sustaining a robust anti-fraud response in digitalized administrative environments.

Enrique Castellares Cuya, José Rengifo Espinal · 0 citations
Review Open access Jul 2026

Penetration Testing in System Security

This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.

Shruti Agarwal, Shilpi Sharma · 1 citation
Review Open access Aug 2026

A Survey on Cybersecurity Threats in Industrial and Information Technology Environments: Advancements and Resilience Through Network Steganographic Techniques

The complex interplay of Operational Technology (OT) and Information Technology (IT) daily supports critical infrastructures managing energy, transportation, manufacturing, and utilities. Due to their importance, the number of attacks targeting IT/OT scenarios has increased. The most sophisticated malware relies on techniques such as encryption, obfuscation, or social engineering. An emerging trend is to use some form of information hiding, mainly to create covert communications cloaked within network traffic. This paper analyzes eight major IT/OT threats in the view of their empowerment via steganography. The goal of this work is to anticipate the evolution of malicious software targeting IT/OT scenarios when endowed with advanced data hiding schemes, i.e., multi level steganography. Our analysis clearly indicates that the ability of cloaking data within IT/OT deployments should be considered a real danger. Moreover, current mitigation techniques are only partially adequate to face such a new-wave of attacks. Hence, we provide some gaps to be filled by researchers and security experts for improving detection techniques and implementing defenses against emerging cybersecurity threats.

Przemysław Szary, Wojciech Mazurczyk, L. Caviglione · 0 citations
Review Open access Jul 2026

AIS Cybersecurity: Challenges, Vulnerabilities, and Mitigation Strategies

Maritime operations rely on the Automatic Identification System (AIS), an open broadcast protocol whose unauthenticated, self-reported messages are easily abused. This survey provides an AIS-first, security-focused synthesis of AIS cybersecurity research. It makes three main contributions. First, it explains AIS protocol mechanics and uses them to derive the main security weaknesses that arise from open VHF broadcast, self-reported data, lack of built-in authentication and replay protection, and GNSS dependence. Second, it organizes AIS threats and mitigations into a unified taxonomy that links attack vectors, technical effects, operational impacts, and security measures across the prevent–detect–respond–recover lifecycle. Third, it assesses practical defenses, including authentication proposals, endpoint and network hardening, behavior-aware analytics, cross-sensor validation, and governance measures. The survey shows that existing work is strongest on anomaly detection and AIS data analytics, whereas standards-compatible authentication, scalable key management, backward-compatible deployment, trust-aware display integration, and operational validation remain open challenges. Consequently, AIS security is likely to require layered, staged, and standards-compatible mitigations rather than a single technical fix. By bringing together cybersecurity, maritime operations, and data-science perspectives, the survey provides practical guidance for securing AIS-based systems and highlights open problems for future standardization and implementation.

Silvie Levy, Ehud Gudess, Danny Hendler · 0 citations
Conference Aug 2026

Real-Time DDoS Detection by Integrated eBPF Telemetry and Machine Learning-enhanced SIEM

Distributed Denial-of-Service (DDoS) attacks remain one of the most disruptive threats to modern web services, overwhelming application resources and degrading service availability. This paper presents a lightweight, virtualized system architecture for real-time DDoS detection that combines kernellevel telemetry collection with machine learning (ML) based analysis. The proposed architecture enables fine-grained, lowoverhead log collection without modifying the web applications because the network and application-level events generated during normal and attack traffic are captured directly at the kernel layer by means of an extended Berkeley Packet Filter (eBPF). The collected logs are then processed within a Security Information and Event Management (SIEM) platform, where ML–based detection models analyze traffic patterns and behavioral features to identify DDoS attacks in near real-time. This architecture improves visibility into attack characteristics while maintaining minimal performance impact on the protected services. The proposed system demonstrates how eBPF-based observability, when integrated with SIEM and ML techniques, can provide an effective, scalable, and modular approach for DDoS detection in virtualized environments. The design is particularly suited for cloud and multi-VM deployments, offering enhanced security monitoring, faster attack detection, and improved operational resilience.

Zeeshan Ali, A. Marotta, W. Tiberti et al. · 0 citations