A Graph-Based Approach to Alert Contextualisation in Security Operations Centres

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Eckhoff, Magnus Wiik, Flydal, Peter Marius, Peters, Siem, Eian, Martin, Halvorsen, Jonas, Mavroeidis, Vasileios, Grov, Gudmund
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908544783089664
author Eckhoff, Magnus Wiik
Flydal, Peter Marius
Peters, Siem
Eian, Martin
Halvorsen, Jonas
Mavroeidis, Vasileios
Grov, Gudmund
author_facet Eckhoff, Magnus Wiik
Flydal, Peter Marius
Peters, Siem
Eian, Martin
Halvorsen, Jonas
Mavroeidis, Vasileios
Grov, Gudmund
contents Interpreting the massive volume of security alerts is a significant challenge in Security Operations Centres (SOCs). Effective contextualisation is important, enabling quick distinction between genuine threats and benign activity to prioritise what needs further analysis. This paper proposes a graph-based approach to enhance alert contextualisation in a SOC by aggregating alerts into graph-based alert groups, where nodes represent alerts and edges denote relationships within defined time-windows. By grouping related alerts, we enable analysis at a higher abstraction level, capturing attack steps more effectively than individual alerts. Furthermore, to show that our format is well suited for downstream machine learning methods, we employ Graph Matching Networks (GMNs) to correlate incoming alert groups with historical incidents, providing analysts with additional insights.
format Preprint
id arxiv_https___arxiv_org_abs_2509_12923
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A Graph-Based Approach to Alert Contextualisation in Security Operations Centres
Eckhoff, Magnus Wiik
Flydal, Peter Marius
Peters, Siem
Eian, Martin
Halvorsen, Jonas
Mavroeidis, Vasileios
Grov, Gudmund
Cryptography and Security
Artificial Intelligence
Interpreting the massive volume of security alerts is a significant challenge in Security Operations Centres (SOCs). Effective contextualisation is important, enabling quick distinction between genuine threats and benign activity to prioritise what needs further analysis. This paper proposes a graph-based approach to enhance alert contextualisation in a SOC by aggregating alerts into graph-based alert groups, where nodes represent alerts and edges denote relationships within defined time-windows. By grouping related alerts, we enable analysis at a higher abstraction level, capturing attack steps more effectively than individual alerts. Furthermore, to show that our format is well suited for downstream machine learning methods, we employ Graph Matching Networks (GMNs) to correlate incoming alert groups with historical incidents, providing analysts with additional insights.
title A Graph-Based Approach to Alert Contextualisation in Security Operations Centres
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2509.12923