Метод зниження рівня хибних спрацювань (False Positives) при моніторингу технік Living off The Land у корпоративних мережах
Анотації
У роботі досліджується проблема критичного перевантаження центрів моніторингу безпеки (SOC) хибними спрацюваннями (False Positives), що виникають під час спроб виявлення атак типу «Living off the Land» (LotL). The paper investigates the critical problem of Security Operations Centers (SOC) being overloaded with false positives during attempts to detect "Living off the Land" (LotL) attacks. Since attackers utilize legitimate system tools (PowerShell, WMI, PsExec), classic signature-based SIEM rules cannot distinguish malicious activity from the routine work of system administrators. This leads to the phenomenon of "alert fatigue" and the missing of actual incidents. To address this issue, a method of contextual security data enrichment is proposed, which integrates technical events with organizational metadata (user role, behavioral profile, asset criticality). The application of this method automates the filtering of legitimate activity and significantly reduces the level of information noise.
URI:
https://ir.lib.vntu.edu.ua/handle/123456789/53306

