A Graph-Based Approach to Alert Contextualisation in Security Operations Centres

πŸ“… 2025-09-16
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
To address the challenge of efficiently distinguishing genuine threats from massive alerts in Security Operations Centers (SOCs), this paper proposes a graph-based alert contextualization method. It constructs an alert relation graph within a sliding time window, aggregating semantically related alerts into structural graph units. Crucially, it introduces a Graph Matching Network (GMN) to enable fine-grained matching between incoming alerts and historical attack patterns, supporting both attack-stage identification and alert prioritization. The method integrates temporal correlation modeling, graph representation learning, and an interpretable graph aggregation mechanism. Experimental results demonstrate significant improvements: +12.3% in attack-chain identification accuracy and AUC for alert ranking. Moreover, it enhances analysts’ ability to compare current alerts with contextual and historical evidence, providing a higher-level, interpretable graph model for alert analysis.

Technology Category

Application Category

πŸ“ Abstract
Interpreting the massive volume of security alerts is a significant challenge in Security Operations Centres (SOCs). Effective contextualisation is important, enabling quick distinction between genuine threats and benign activity to prioritise what needs further analysis.This paper proposes a graph-based approach to enhance alert contextualisation in a SOC by aggregating alerts into graph-based alert groups, where nodes represent alerts and edges denote relationships within defined time-windows. By grouping related alerts, we enable analysis at a higher abstraction level, capturing attack steps more effectively than individual alerts. Furthermore, to show that our format is well suited for downstream machine learning methods, we employ Graph Matching Networks (GMNs) to correlate incoming alert groups with historical incidents, providing analysts with additional insights.
Problem

Research questions and friction points this paper is trying to address.

Interpreting massive security alert volumes in SOCs
Distinguishing genuine threats from benign activities
Enhancing alert contextualization via graph-based grouping
Innovation

Methods, ideas, or system contributions that make the work stand out.

Graph-based alert grouping technique
Time-windowed relationship edge definition
Graph Matching Networks for correlation
πŸ”Ž Similar Papers
M
Magnus Wiik Eckhoff
Norwegian Defence Research Establishment, University of Oslo
P
Peter Marius Flydal
mnemonic AS
S
Siem Peters
mnemonic AS
M
Martin Eian
mnemonic AS
J
Jonas Halvorsen
Norwegian Defence Research Establishment, University of Oslo
Vasileios Mavroeidis
Vasileios Mavroeidis
Associate Professor of Cybersecurity, University of Oslo
CybersecurityCyber Threat IntelligenceSecurity Automation and OrchestrationIncident ResponseStandardization
Gudmund Grov
Gudmund Grov
Senior Scientist, Norwegian Defence Research Establishment
SecurityFormal MethodsAutomated Reasoning